Splunk Search

Timechart last month to prior month comparison with trend

timm747747
Path Finder

Hi, I am trying to compare the number of events from last month to the prior month. So January and February and display the trend line using timechart. I am trying this search:

eventtype=incident type=Email earliest=-2mon (classification=Malicious OR classification="Malware") | timechart span=1month count

The problem is that it is displaying this month (March) compared to last month and not last month to February.

Any help would be greatly appreciated!!

T

skoelpin
SplunkTrust
SplunkTrust

Try this

eventtype=incident type=Email earliest=-2mon (classification=Malicious OR classification="Malware") earliest=-2month@month latest=-1month@month
| timechart span=1month count
| timewrap 1month
0 Karma

logloganathan
Motivator

you can select the time range from January 1st to February 28th in splunk

eventtype=incident type=Email classification=Malicious OR classification="Malware" | timechart span=1m count

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...