Splunk Search

Looking for date wise Incidents resolved count by each user

Gousa
New Member

i am trying to pull incidents resolved by each user in date wise . can any one help me how to form the below table with count

User Name10/4/202110/5/202110/6/2021Grand Total
AAAA 3 3
BBBBB2  2
CCCCC31 4
DDD1  1
Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Use timechart with span of one day by user to get a timeseries. Then transpose the results. Finally you can do addtotals.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...