Splunk Search

compare event count today vs yesterday vs last week vs prior week

john_q
Explorer

Hi,

i want to compare event count today with yesterday,last week and prior week using timewarp complete day like day starting to till now

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Will these work?

... | bin span=1d _time | stats count by _time

And same search but 1w instead of 1d (for weeks instead of days)

0 Karma

john_q
Explorer

hi @jkat54 thnaks for your answer but I want to compare the today event count with yesterday , last and prior week event counts like in the form of line chart like 4 legends.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Yeah, so you do the search above and select the weeks/days you want to chart with your time picker.

0 Karma

john_q
Explorer

can you provide a sample full search for this??

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...