Splunk Search

Looking for date wise Incidents resolved count by each user

Gousa
New Member

i am trying to pull incidents resolved by each user in date wise . can any one help me how to form the below table with count

User Name10/4/202110/5/202110/6/2021Grand Total
AAAA 3 3
BBBBB2  2
CCCCC31 4
DDD1  1
Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Use timechart with span of one day by user to get a timeseries. Then transpose the results. Finally you can do addtotals.

0 Karma
Get Updates on the Splunk Community!

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...