Splunk Search

How to show the results of a query month wise in splunk?

avi123
Explorer

Hi All,

I have a query which returns results for a particular month like how many tickets breached SLA. The month and year is hardcoded to the query. Now, I am wanting not to hard code the month in the query, instead use it in output - so that user can select the month to get the results. Could you please help here?

Query Results:

TicketCountSLABreached(TCSB)  TotalTicketCount(TTC)  IncResolutionTime(TCSB/TTC*100)    TimeStamp

2                                                                    3                                              66.667                                                             February 2024

0 Karma

avi123
Explorer

This is output for a splunk query returning search results

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...