Splunk Search

time span = week

gowtham08091
Explorer

Hello, I am trying to span for 1 week and 1 month chart from the summary index search, but When in use | bin span=1w, instead of showing the last or latest data of week it is summing the weeks total. I am looking for trend chart, where to display first or last data of a week or month.

i used same bin command earlier and but this time one difference is i a, using stats.

I use the query in the following format  

gowtham08091_0-1595261922992.pnggowtham08091_1-1595261935357.png

 

Labels (3)
Tags (3)
0 Karma
1 Solution

gowtham08091
Explorer

@anilchaithu 

 

I am looking for a trend report like weekly and monthly trend, like. Weekly trend should how the result from last data of a week and monthly trend to show the data from last day of a month. (not the cumulative sum of week and month) 

View solution in original post

0 Karma

anilchaithu
Builder

@gowtham08091 

Its the bin functionality to sum the field values for the given span. 

what do you mean by "to display first or last data of a week or month"? Do you want to show only a single data point?

 

 

0 Karma

gowtham08091
Explorer

@anilchaithu 

 

I am looking for a trend report like weekly and monthly trend, like. Weekly trend should how the result from last data of a week and monthly trend to show the data from last day of a month. (not the cumulative sum of week and month) 

0 Karma

gowtham08091
Explorer

Thanks for the feedback, with your comment i found that i am missing the _time in my search and i get the expected results when I add _time in dedup

 

Thanks

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...