How can I compare the t_done event in Splunk Web performance for last week's data and current data?
hi rck,
that is the example using timewrap
:
source="Perfmon:CPU Load" counter="% Processor Time" host="SERVER01" earliest=-1d@d latest=-0d@d
| timechart avg(Value) span=1h
| timewrap w
| where strftime(_time, "%A") == " day of the week"
For more informations, try following this link:
https://answers.splunk.com/answers/60295/comparing-time-ranges-one-report.html
Try using the Timewrap app. You can use it to compare two time ranges by adding it your search.
https://splunkbase.splunk.com/app/1645/
t_done=* earliest=-2w@w latest=@w | timechart avg(t_done) | timewrap w