Splunk Search

How to get data for latest 10 weeks in splunk chart?

Vish
Explorer

I have a bar chart in splunk which has x-axis as each week from 2019 to 2023 and y-axis as count of data.

Now i want to get only the latest 10 weeks in x-axis

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Vish ,

did you tried to use 

earliest=-10w

in your main search?

otherwise, if you're using timechart command, you could use the "bin" option as described at https://docs.splunk.com/Documentation/SCS/current/SearchReference/TimechartCommandSyntaxDetails 

ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...