Splunk Search

How do I get my top 10 search to return results per month for the last three months?

New Member

Hello I have a Top 10 query and it's run using earliest of -3mon to latest @mon

So I would like to be able to return the top 10 results displayed per month

e.g.

Jan       Count    Feb       Count    Mar       Count             
item 1    xxxx     item 1    xxxx     item 1    xxxx             
item 2    xxxx     item 2    xxxx     item 2    xxxx             
item 3    xxxx     item 3    xxxx     item 3    xxxx  
Tags (3)
0 Karma

Revered Legend

Try like this

your base search | eval Month=strftime(_time,"%m/%Y") | top limit=10 item by Month
0 Karma