Splunk Search

How to show the results of a query month wise in splunk?

avi123
Explorer

Hi All,

I have a query which returns results for a particular month like how many tickets breached SLA. The month and year is hardcoded to the query. Now, I am wanting not to hard code the month in the query, instead use it in output - so that user can select the month to get the results. Could you please help here?

Query Results:

TicketCountSLABreached(TCSB)  TotalTicketCount(TTC)  IncResolutionTime(TCSB/TTC*100)    TimeStamp

2                                                                    3                                              66.667                                                             February 2024

0 Karma

avi123
Explorer

This is output for a splunk query returning search results

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...