Hi everyone,
I am searching data in Splunk, after different steps, I have now this table:
_time | count | Type |
Mon Sep 12 00:00:00 2022 | 820 | 1 |
Mon Sep 12 00:00:00 2022 | 885 | 2 |
Tue Sep 13 00:00:00 2022 | 773 | 1 |
Tue Sep 13 00:00:00 2022 | 922 | 2 |
Wed Sep 14 00:00:00 2022 | 825 | 1 |
Wed Sep 14 00:00:00 2022 | 844 | 2 |
Thu Sep 15 00:00:00 2022 | 748 | 1 |
Thu Sep 15 00:00:00 2022 | 943 | 2 |
Fri Sep 16 00:00:00 2022 | 794 | 1 |
Fri Sep 16 00:00:00 2022 | 890 | 2 |
Sat Sep 17 00:00:00 2022 | 684 | 1 |
Sat Sep 17 00:00:00 2022 | 793 | 2 |
Sun Sep 18 00:00:00 2022 | 737 | 1 |
Sun Sep 18 00:00:00 2022 | 795 | 2 |
Mon Sep 19 00:00:00 2022 | 764 | 1 |
Mon Sep 19 00:00:00 2022 | 890 | 2 |
Tue Sep 20 00:00:00 2022 | 792 | 1 |
Tue Sep 20 00:00:00 2022 | 876 | 2 |
Wed Sep 21 00:00:00 2022 | 754 | 1 |
Wed Sep 21 00:00:00 2022 | 853 | 2 |
Thu Sep 22 00:00:00 2022 | 784 | 1 |
Thu Sep 22 00:00:00 2022 | 883 | 2 |
Fri Sep 23 00:00:00 2022 | 731 | 1 |
Fri Sep 23 00:00:00 2022 | 820 | 2 |
Sat Sep 24 00:00:00 2022 | 691 | 1 |
Sat Sep 24 00:00:00 2022 | 788 | 2 |
Sun Sep 25 00:00:00 2022 | 726 | 1 |
Sun Sep 25 00:00:00 2022 | 762 | 2 |
Mon Sep 26 00:00:00 2022 | 403 | 1 |
Mon Sep 26 00:00:00 2022 | 431 | 2 |
Actually there are more than 2 types but I just put here 2 for simplify.
For now I can view the trending of data for each type thanks to Trellis, by 7 days per week.
But I want to have another view to have data display by each type , compare the same day of different weeks. Something like this:
Do you have any idea please?
Thanks,
Julia
Have a look at the | timewrap function. I believe that should cover what you're looking for.