Splunk Search

time span = week

gowtham08091
Explorer

Hello, I am trying to span for 1 week and 1 month chart from the summary index search, but When in use | bin span=1w, instead of showing the last or latest data of week it is summing the weeks total. I am looking for trend chart, where to display first or last data of a week or month.

i used same bin command earlier and but this time one difference is i a, using stats.

I use the query in the following format  

gowtham08091_0-1595261922992.pnggowtham08091_1-1595261935357.png

 

Labels (3)
Tags (3)
0 Karma
1 Solution

gowtham08091
Explorer

@anilchaithu 

 

I am looking for a trend report like weekly and monthly trend, like. Weekly trend should how the result from last data of a week and monthly trend to show the data from last day of a month. (not the cumulative sum of week and month) 

View solution in original post

0 Karma

anilchaithu
Builder

@gowtham08091 

Its the bin functionality to sum the field values for the given span. 

what do you mean by "to display first or last data of a week or month"? Do you want to show only a single data point?

 

 

0 Karma

gowtham08091
Explorer

@anilchaithu 

 

I am looking for a trend report like weekly and monthly trend, like. Weekly trend should how the result from last data of a week and monthly trend to show the data from last day of a month. (not the cumulative sum of week and month) 

0 Karma

gowtham08091
Explorer

Thanks for the feedback, with your comment i found that i am missing the _time in my search and i get the expected results when I add _time in dedup

 

Thanks

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...