Splunk Search

how to group by month for yearly data.

rajhemant26
New Member

Hello everyone.

Want to display the output only for the time which crosses 18 months (earliest time)

Tags (1)
0 Karma

iamarkaprabha
Contributor

Hi ,
Can you use timechart instead of stats and use span of 1month over there

Vijeta
Influencer

@rajhemant26 Your query seems to be fine. Have you tried doing a simple search for past 6 months and are you able to get data for any other month except September for the index you have used? May be you dont have permission to search only on 1 month data at a timr. Try searching on the index for "All time" and see if you see data from August, July, June etc.

0 Karma

iamarkaprabha
Contributor

I second you Vijeta

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...