在 Splunk 中,我想以每周累积的方式显示数据,但下面的查询是从“周四到周四”而不是“周一到周日”计算数据。
请帮忙。
index=c sourcetype=c | timechart count(eval(State = "Closed" OR State= "Resolved")) as "Closed", count(eval(State = "Assigned" OR State= "Open")) as "Still Open", count(eval(State = "Pending")) as "Pending" span=1w | streamstats sum(*) as *