Splunk Search

Timechart last month to prior month comparison with trend

timm747747
Path Finder

Hi, I am trying to compare the number of events from last month to the prior month. So January and February and display the trend line using timechart. I am trying this search:

eventtype=incident type=Email earliest=-2mon (classification=Malicious OR classification="Malware") | timechart span=1month count

The problem is that it is displaying this month (March) compared to last month and not last month to February.

Any help would be greatly appreciated!!

T

skoelpin
SplunkTrust
SplunkTrust

Try this

eventtype=incident type=Email earliest=-2mon (classification=Malicious OR classification="Malware") earliest=-2month@month latest=-1month@month
| timechart span=1month count
| timewrap 1month
0 Karma

logloganathan
Motivator

you can select the time range from January 1st to February 28th in splunk

eventtype=incident type=Email classification=Malicious OR classification="Malware" | timechart span=1m count

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...