You can use the now() time and eval to create the timestamps for your query - if you know when the search runs.
If you are running the query in the following month you can use the following search command:
index="cyber" sourcetype=response queue = "Incident" status ="resolved"
| eval startstamp=strftime(relative_time(now(),"-mon@mon"),"%Y-%m-%d %H:%M:%S"), endstamp=strftime(relative_time(now(),"@mon"),"%Y-%m-%d %H:%M:%S")
| where Dates_Created >= startstamp AND Dates_Created < endstamp
| dedup ticket
| stats count AS Sept`
... View more