- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Gathering Six Months of Trend Data
I'm still relatively new to Splunk and am having trouble understanding Timechart and the proper syntax for it. I'm looking to gather 6 months worth of Trend data for compliance purposes. Currently, I've got the following in order to get the initial (monthly) data point so that each month it updates to the new 6 month window:
search query | dedup 2 items | stats count(eval(state="passed")) AS Passed, count(eval(state="failed")) AS Failed | eval Percent_Compliance=(100-((Failed/Passed)*100))
I assume that I want to set the search range as 6 months instead of 1 month, but outside of that I don't really understand how to implement timechart or if there is a better solution. Thank you in advance.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/01cdb/01cdb67a2f1abf8e2322590f55c3bebcd70020e0" alt="renjith_nair renjith_nair"
@giventofly08 ,
If you want to see a trend of last 6 months over 1 month span,
try
search query earliest=-6m@m| dedup 2 items | timechart span=1mon count(eval(state="passed")) AS Passed, count(eval(state="failed")) AS Failed | eval Percent_Compliance=(100-((Failed/Passed)*100))
What goes around comes around. If it helps, hit it with Karma 🙂
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's returning 0 results at this moment. Perhaps I missed something? For simplicity sake here's the whole thing:
index=bigfix sourcetype="bigfix:compliance" source_severity="high" state="passed" OR state="failed" earliest=-6m@m | dedup comp_id check_id | timechart span=1mon count(eval(state="passed")) AS Passed, count(eval(state="failed")) AS Failed | eval Percent_Compliance=(100-((Failed/Passed)*100))
That's generating 0 results, where as before the timechart addition it would show the checks that passed, failed, and the percentage of it.
Thanks for your help!
data:image/s3,"s3://crabby-images/1a552/1a552ff33d37f94e7c5bc13132edaa973c529815" alt=""