Splunk Search
Highlighted

How to track the count of IP addresses on each server week over week for 4 weeks?

New Member

I need to see how many IP addresses are on each server for the current week, last week, 2 weeks ago, and 3 weeks ago. This needs to be tracked week over week and display a total of 4 weeks, like in the example below.

alt text

0 Karma
Highlighted

Re: How to track the count of IP addresses on each server week over week for 4 weeks?

Legend

Your search will look something like this

    index=foo sourcetype=bar earliest=-4w@w | eval wk=case(relative_time(_time, "-1w@w")<_time, "This Week", relative_time(_time, "-2w@w")<_time AND relative_time(_time, "-1w@w")>_time, "1 week",   and so on and so forth | chart count over server by wk
0 Karma
Highlighted

Re: How to track the count of IP addresses on each server week over week for 4 weeks?

SplunkTrust
SplunkTrust
0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.