Splunk Search

How to compare data by the same day of different weeks?

Julia1231
Communicator

Hi everyone,

I am searching data in Splunk, after different steps, I have now this table:

 

_time count Type
Mon Sep 12 00:00:00 2022 820 1
Mon Sep 12 00:00:00 2022 885 2
Tue Sep 13 00:00:00 2022 773 1
Tue Sep 13 00:00:00 2022 922 2
Wed Sep 14 00:00:00 2022 825 1
Wed Sep 14 00:00:00 2022 844 2
Thu Sep 15 00:00:00 2022 748 1
Thu Sep 15 00:00:00 2022 943 2
Fri Sep 16 00:00:00 2022 794 1
Fri Sep 16 00:00:00 2022 890 2
Sat Sep 17 00:00:00 2022 684 1
Sat Sep 17 00:00:00 2022 793 2
Sun Sep 18 00:00:00 2022 737 1
Sun Sep 18 00:00:00 2022 795 2
Mon Sep 19 00:00:00 2022 764 1
Mon Sep 19 00:00:00 2022 890 2
Tue Sep 20 00:00:00 2022 792 1
Tue Sep 20 00:00:00 2022 876 2
Wed Sep 21 00:00:00 2022 754 1
Wed Sep 21 00:00:00 2022 853 2
Thu Sep 22 00:00:00 2022 784 1
Thu Sep 22 00:00:00 2022 883 2
Fri Sep 23 00:00:00 2022 731 1
Fri Sep 23 00:00:00 2022 820 2
Sat Sep 24 00:00:00 2022 691 1
Sat Sep 24 00:00:00 2022 788 2
Sun Sep 25 00:00:00 2022 726 1
Sun Sep 25 00:00:00 2022 762 2
Mon Sep 26 00:00:00 2022 403 1
Mon Sep 26 00:00:00 2022 431 2

Actually there are more than 2 types but I just put here 2 for simplify.

For now I can view the trending of data for each type thanks to Trellis, by 7 days per week.

Julia1231_0-1664181615580.png


But I want to have another view to have data display by each type , compare the same day of different weeks. Something like this:

Julia1231_3-1664183301588.png

Do you have any idea please?

Thanks,

Julia

Labels (5)
Tags (1)
0 Karma

andrew_nelson
Communicator

Have a look at the  | timewrap function. I believe that should cover what you're looking for.

timewrap - Splunk Documentation

0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...