Splunk Search

Comparing last year to this year

JovanMilosevic
Path Finder

Hi,

I have 3 single values displaying YTD, MTD and Today's figures.

What I'd like to do is have another 3 single values that give last year's equivalent figures, i.e.

Jan 1 to Sept 17 2011 inclusive, Sept 1 to Sept 17 2011 inclusive, and Sept 17 2011.

Just can't seem to work out what time modifiers I should use.

Thanks in advance.

Tags (1)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi JovanMilosevic

try the following time setting after your search string:

Jan 1 to Sept 17 2011 inclusive -> earliest=-y@y latest=-y@+d@d

Sept 1 to Sept 17 2011 inclusive -> earliest=-y@mon latest=-y@+d@d

Sept 17 2011 -> earliest=-y@d@d latest=-y@+d@d

cheers,

MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi JovanMilosevic

try the following time setting after your search string:

Jan 1 to Sept 17 2011 inclusive -> earliest=-y@y latest=-y@+d@d

Sept 1 to Sept 17 2011 inclusive -> earliest=-y@mon latest=-y@+d@d

Sept 17 2011 -> earliest=-y@d@d latest=-y@+d@d

cheers,

MuS

MuS
SplunkTrust
SplunkTrust

yes, the last @d snaps to the current day, without it it uses the actual time. you can test it in the manager by clicking the timepicker and use the advanced search language. the docs about the time range are here http://docs.splunk.com/Documentation/Splunk/4.3.4/User/ChangeTheTimeRangeOfYourSearch

0 Karma

JovanMilosevic
Path Finder

Thanks for this. For the Sep 17 search, is it possible to get the search to retrieve records for up to the current time on that day, rather than the whole day ?

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...