Splunk Search

How to compare data by the same day of different weeks?

Julia1231
Communicator

Hi everyone,

I am searching data in Splunk, after different steps, I have now this table:

 

_time count Type
Mon Sep 12 00:00:00 2022 820 1
Mon Sep 12 00:00:00 2022 885 2
Tue Sep 13 00:00:00 2022 773 1
Tue Sep 13 00:00:00 2022 922 2
Wed Sep 14 00:00:00 2022 825 1
Wed Sep 14 00:00:00 2022 844 2
Thu Sep 15 00:00:00 2022 748 1
Thu Sep 15 00:00:00 2022 943 2
Fri Sep 16 00:00:00 2022 794 1
Fri Sep 16 00:00:00 2022 890 2
Sat Sep 17 00:00:00 2022 684 1
Sat Sep 17 00:00:00 2022 793 2
Sun Sep 18 00:00:00 2022 737 1
Sun Sep 18 00:00:00 2022 795 2
Mon Sep 19 00:00:00 2022 764 1
Mon Sep 19 00:00:00 2022 890 2
Tue Sep 20 00:00:00 2022 792 1
Tue Sep 20 00:00:00 2022 876 2
Wed Sep 21 00:00:00 2022 754 1
Wed Sep 21 00:00:00 2022 853 2
Thu Sep 22 00:00:00 2022 784 1
Thu Sep 22 00:00:00 2022 883 2
Fri Sep 23 00:00:00 2022 731 1
Fri Sep 23 00:00:00 2022 820 2
Sat Sep 24 00:00:00 2022 691 1
Sat Sep 24 00:00:00 2022 788 2
Sun Sep 25 00:00:00 2022 726 1
Sun Sep 25 00:00:00 2022 762 2
Mon Sep 26 00:00:00 2022 403 1
Mon Sep 26 00:00:00 2022 431 2

Actually there are more than 2 types but I just put here 2 for simplify.

For now I can view the trending of data for each type thanks to Trellis, by 7 days per week.

Julia1231_0-1664181615580.png


But I want to have another view to have data display by each type , compare the same day of different weeks. Something like this:

Julia1231_3-1664183301588.png

Do you have any idea please?

Thanks,

Julia

Labels (5)
Tags (1)
0 Karma

andrew_nelson
Path Finder

Have a look at the  | timewrap function. I believe that should cover what you're looking for.

timewrap - Splunk Documentation

0 Karma
Get Updates on the Splunk Community!

Announcing General Availability of Splunk Incident Intelligence!

Digital transformation is real! Across industries, companies big and small are going through rapid digital ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...