Splunk Search

I need get the no.of events over 30 days, 60days and 90 days over column cart

haripotu
Loves-to-Learn Everything

Hi, I need to get the no.of events happened over last 90 days, 60 days, 30 days in one column chart. Using eval, if. Use the if command to group the events by their time stamps.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
search
| bin _time span=30d
| stats count by _time
0 Karma

haripotu
Loves-to-Learn Everything

hey how can i get the no.of events between 30 days and 60 days

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

By using the bin command, the _time is set to the begging of the 30day period, so 30 day count will be the most recent count and 60 will be the previous count

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...