I need to see how many IP addresses are on each server for the current week, last week, 2 weeks ago, and 3 weeks ago. This needs to be tracked week over week and display a total of 4 weeks, like in the example below.
Also, look at Time wrap app https://splunkbase.splunk.com/app/1645/
http://blogs.splunk.com/2013/12/04/comparing-week-over-week-results/
Your search will look something like this
index=foo sourcetype=bar earliest=-4w@w | eval wk=case(relative_time(_time, "-1w@w")<_time, "This Week", relative_time(_time, "-2w@w")<_time AND relative_time(_time, "-1w@w")>_time, "1 week", and so on and so forth | chart count over server by wk