I have this below search and would like to add another line to include the week previous showing how it compares with the last 7 days.
index=summary report=otl_engineering_jiracsatresults Key="**" Assignee="**" Classification="**"
| dedup Key
| eval dateEpoch = strptime(Date, "%Y-%m-%d %H:%M")
| eval today = now()
| eval daysAgo = round(((today - dateEpoch)/60/60/24), 0)
| rex field=Date "(?<day>^\d{4}-\d{2}-\d{2}) \d{2}:\d{2}$"
| table Key, Summary, Reporter, Assignee, Classification, "CSAT Rate", "CSAT Rating Comment", Date, daysAgo, day
| search daysAgo <= 7
| stats avg("CSAT Rate") as AverageCustomerRating by day
Hi try using timewrap
command at the end of your search with timechart.
Refer: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Timewrap
Hi try using timewrap
command at the end of your search with timechart.
Refer: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Timewrap