Splunk Search

compare event count today vs yesterday vs last week vs prior week

john_q
Explorer

Hi,

i want to compare event count today with yesterday,last week and prior week using timewarp complete day like day starting to till now

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Will these work?

... | bin span=1d _time | stats count by _time

And same search but 1w instead of 1d (for weeks instead of days)

0 Karma

john_q
Explorer

hi @jkat54 thnaks for your answer but I want to compare the today event count with yesterday , last and prior week event counts like in the form of line chart like 4 legends.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Yeah, so you do the search above and select the weeks/days you want to chart with your time picker.

0 Karma

john_q
Explorer

can you provide a sample full search for this??

0 Karma
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...