Splunk Search

how to group by month for yearly data.

rajhemant26
New Member

Hello everyone.

Want to display the output only for the time which crosses 18 months (earliest time)

Tags (1)
0 Karma

iamarkaprabha
Contributor

Hi ,
Can you use timechart instead of stats and use span of 1month over there

Vijeta
Influencer

@rajhemant26 Your query seems to be fine. Have you tried doing a simple search for past 6 months and are you able to get data for any other month except September for the index you have used? May be you dont have permission to search only on 1 month data at a timr. Try searching on the index for "All time" and see if you see data from August, July, June etc.

0 Karma

iamarkaprabha
Contributor

I second you Vijeta

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...