Hi All,
I have a query which returns results for a particular month like how many tickets breached SLA. The month and year is hardcoded to the query. Now, I am wanting not to hard code the month in the query, instead use it in output - so that user can select the month to get the results. Could you please help here?
Query Results:
TicketCountSLABreached(TCSB) TotalTicketCount(TTC) IncResolutionTime(TCSB/TTC*100) TimeStamp
2 3 66.667 February 2024
This is output for a splunk query returning search results