Hi, I am trying to compare the number of events from last month to the prior month. So January and February and display the trend line using timechart. I am trying this search:
eventtype=incident type=Email earliest=-2mon (classification=Malicious OR classification="Malware") | timechart span=1month count
The problem is that it is displaying this month (March) compared to last month and not last month to February.
Any help would be greatly appreciated!!
T
Try this
eventtype=incident type=Email earliest=-2mon (classification=Malicious OR classification="Malware") earliest=-2month@month latest=-1month@month
| timechart span=1month count
| timewrap 1month
you can select the time range from January 1st to February 28th in splunk
eventtype=incident type=Email classification=Malicious OR classification="Malware" | timechart span=1m count