Splunk Search

Trendline over longer historical period

Path Finder

I'm generating a timechart, with a 5 period simple moving average. I'm only searching over a week, with the span set to 1 day. This results in only 3 moving average data points.

What would be ideal is to get the moving average data points from the earlier data (days in previous week) added to the result of my 1 week search. I investigated the possibility of extending the search over two weeks, and then truncating the results, but I do not think this is possible. 

Is what I'm trying at all possible?

Labels (1)
0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!