Splunk Search

Timechart last month to prior month comparison with trend

timm747747
Path Finder

Hi, I am trying to compare the number of events from last month to the prior month. So January and February and display the trend line using timechart. I am trying this search:

eventtype=incident type=Email earliest=-2mon (classification=Malicious OR classification="Malware") | timechart span=1month count

The problem is that it is displaying this month (March) compared to last month and not last month to February.

Any help would be greatly appreciated!!

T

skoelpin
SplunkTrust
SplunkTrust

Try this

eventtype=incident type=Email earliest=-2mon (classification=Malicious OR classification="Malware") earliest=-2month@month latest=-1month@month
| timechart span=1month count
| timewrap 1month
0 Karma

logloganathan
Motivator

you can select the time range from January 1st to February 28th in splunk

eventtype=incident type=Email classification=Malicious OR classification="Malware" | timechart span=1m count

Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...