Splunk Search

Wants to compare last 4 hours data with last 2 days data over the same time

Sishad
Explorer

Hi Splunk experts,

I want to compare the response code of our API for last 4 hours with last 2 days data over the same time.
And if possible I would need results in a chart/table format where it shows the data as below.

<Reponse Codes | Last 4 Hours | Yesterday | Day before Yesterday>

As of now i am getting results in hours wise.
Can we achieve this one in Splunk ? Can you guys please guide me in the right direction to achieve this.

 

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Yes, the timewrap command can take the output from a timechart to create multiple lines over the 4 hour period

View solution in original post

Sishad
Explorer

Thanks @ITWhisperer for your suggestion.😊 

I was able to do produce the requested data via this command.

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Start by changing the time period on your search to (earliest=now-4h latest=now) OR (earliest=-1d-4h latest=-1d) OR (earliest=-2d-4h latest=-2d)

0 Karma

Sishad
Explorer

But I was looking to can show these 3 timeline values as a chart/table.
So that I can create a report on this and send out email to my team.
Can this be achieved ?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Yes, the timewrap command can take the output from a timechart to create multiple lines over the 4 hour period

Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...