Splunk Search

Hi everyone, can someone please tl how can we set up a report where we are fetching last 6 month period

shivangisharma
New Member

for ex: if i am running the report on 5th of may, i will need the data from 1st of November till 30 apri and i l need to run this report every month for last 6 months , m on 6.x

how can i set this report so that whenever we run the report for the last months period, it does not include current month..Thank you.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

To start 6 months ago, use earliest=-6mon@mon. To end at the beginning of the current month, use latest=@mon.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...