<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple Time Spans in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670705#M54889</link>
    <description>&lt;P&gt;I am trying to make a query which will give me the result of unique file names with month in column and a time span of 1 hour in row. Below is my query :&lt;BR /&gt;index="app_cleo_db"&lt;BR /&gt;origname="GEAC_Payroll*"&lt;BR /&gt;| rex "\sorigname=\"GEAC_Payroll\((?&amp;lt;digits&amp;gt;\d+)\)\d{8}_\d{6}\.xml\""&lt;BR /&gt;| search origname="*.xml"&lt;BR /&gt;| eval Date = strftime(_time, "%Y-%m-%d %H:00:00")&lt;BR /&gt;| eval DateOnly = strftime(_time, "%Y-%m-%d")&lt;BR /&gt;| transaction DateOnly, origname&lt;BR /&gt;| timechart count by DateOnly&lt;/P&gt;&lt;P&gt;But it is giving me an output with date as well as timestamp in the row like below:&lt;/P&gt;&lt;P&gt;_time 2023-12-02 2023-12-03&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02 00:00:00&lt;/TD&gt;&lt;TD&gt;8&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02 00:30:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02 01:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;7&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02 01:30:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02 02:00:00&lt;/TD&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02 02:30:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02 00:00:00&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-03 00:30:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-03 01:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-03 01:30:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;20&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-03 02:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-03 02:30:00&lt;/TD&gt;&lt;TD&gt;34&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want the result to look like below&lt;/P&gt;&lt;P&gt;_time 2023-12-02 2023-12-03&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;00:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;01:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;02:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;03:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    <pubDate>Mon, 04 Dec 2023 20:20:38 GMT</pubDate>
    <dc:creator>sujata_nandi</dc:creator>
    <dc:date>2023-12-04T20:20:38Z</dc:date>
    <item>
      <title>Multiple Time Spans</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670705#M54889</link>
      <description>&lt;P&gt;I am trying to make a query which will give me the result of unique file names with month in column and a time span of 1 hour in row. Below is my query :&lt;BR /&gt;index="app_cleo_db"&lt;BR /&gt;origname="GEAC_Payroll*"&lt;BR /&gt;| rex "\sorigname=\"GEAC_Payroll\((?&amp;lt;digits&amp;gt;\d+)\)\d{8}_\d{6}\.xml\""&lt;BR /&gt;| search origname="*.xml"&lt;BR /&gt;| eval Date = strftime(_time, "%Y-%m-%d %H:00:00")&lt;BR /&gt;| eval DateOnly = strftime(_time, "%Y-%m-%d")&lt;BR /&gt;| transaction DateOnly, origname&lt;BR /&gt;| timechart count by DateOnly&lt;/P&gt;&lt;P&gt;But it is giving me an output with date as well as timestamp in the row like below:&lt;/P&gt;&lt;P&gt;_time 2023-12-02 2023-12-03&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02 00:00:00&lt;/TD&gt;&lt;TD&gt;8&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02 00:30:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02 01:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;7&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02 01:30:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02 02:00:00&lt;/TD&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02 02:30:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02 00:00:00&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-03 00:30:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-03 01:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-03 01:30:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;20&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-03 02:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-03 02:30:00&lt;/TD&gt;&lt;TD&gt;34&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want the result to look like below&lt;/P&gt;&lt;P&gt;_time 2023-12-02 2023-12-03&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;00:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;01:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;02:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;03:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 04 Dec 2023 20:20:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670705#M54889</guid>
      <dc:creator>sujata_nandi</dc:creator>
      <dc:date>2023-12-04T20:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Time Spans</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670724#M54892</link>
      <description>&lt;P&gt;The span of a timechart is controlled with the syntax&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| timechart span=1h count&lt;/LI-CODE&gt;&lt;P&gt;your example allows timechart to choose its own span based on the data volume.&lt;/P&gt;&lt;P&gt;You can format _time after the timechart&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval _time=strftime(_time, "%H:%M:%S")&lt;/LI-CODE&gt;&lt;P&gt;Note that if you do that, you will not be able to show that on a timechart, as _time is no longer a _time field in Splunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 22:15:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670724#M54892</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-12-04T22:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Time Spans</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670792#M54895</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you for your help, I tried to workout your recommendation and the query looks like below:&lt;/P&gt;&lt;P&gt;index="app_cleo_db"&lt;BR /&gt;origname="GEAC_Payroll*"&lt;BR /&gt;| rex "\sorigname=\"GEAC_Payroll\((?&amp;lt;digits&amp;gt;\d+)\)\d{8}_\d{6}\.xml\""&lt;BR /&gt;| search origname="*.xml"&lt;BR /&gt;| eval Date = strftime(_time, "%Y-%m-%d %H:00:00")&lt;BR /&gt;| eval DateOnly = strftime(_time, "%Y-%m-%d")&lt;BR /&gt;| transaction DateOnly, origname&lt;BR /&gt;| timechart span=1h count by DateOnly&lt;BR /&gt;| eval _time=strftime(_time, "%H:%M:%S")&lt;BR /&gt;&lt;BR /&gt;But this is still giving me the time for both the dates if I try to run my query for 2 days :&lt;/P&gt;&lt;P&gt;_time 2023-12-02 2023-12-03&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;00:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;01:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;02:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;03:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;00:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;01:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;02:00:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;03:00:00&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 05 Dec 2023 11:18:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670792#M54895</guid>
      <dc:creator>sujata_nandi</dc:creator>
      <dc:date>2023-12-05T11:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Time Spans</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670819#M54899</link>
      <description>&lt;P&gt;No, wait.&lt;/P&gt;&lt;P&gt;The timechart works with time automatically. You don't add "by DateOnly" because then it will treat your DateOnly field as a categorizing field.&lt;/P&gt;&lt;PRE&gt;| timechart span=1h count by DateOnly&lt;/PRE&gt;&lt;P&gt;This will count how many values _for each value of DateOnly field_ is per each span (in your case - per each hour).&lt;/P&gt;&lt;P&gt;See this run-anywhere example:&lt;/P&gt;&lt;PRE&gt;| makeresults count=2&lt;BR /&gt;| streamstats count &lt;BR /&gt;| eval _time=_time-count*7200 &lt;BR /&gt;| fields - count&lt;/PRE&gt;&lt;P&gt;This will give you two timestamps - one two hours ago and one for hours ago.&lt;/P&gt;&lt;P&gt;If you simply do&lt;/P&gt;&lt;PRE&gt;| timechart span=1h count by hour&lt;/PRE&gt;&lt;P&gt;You'll get a decent result showing you that for each of those hours you got one event. Which is OK.&lt;/P&gt;&lt;P&gt;But if you do somehing akin to what you did before which means your whole example would look like this:&lt;/P&gt;&lt;PRE&gt;| makeresults count=2&lt;BR /&gt;| streamstats count &lt;BR /&gt;| eval _time=_time-count*7200 &lt;BR /&gt;| fields - count&lt;BR /&gt;| eval DateHour=strftime(_time,"%H")&lt;BR /&gt;| timechart span=1h count by DateHour&lt;/PRE&gt;&lt;P&gt;Your results will turn to this (I ran this at 13:58):&lt;/P&gt;&lt;P&gt;_time 09 11&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;2023-12-05 09:00&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-05 11:00&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Because within the 9-10 hour you have your DateHour of "09" and no encounters of value "11" there (hence the corresponding counts. And within the hour 11-12, you have 0 and 1 counts.&lt;/P&gt;&lt;P&gt;So if you want to have your timechart with the time formatted properly, you don't add the "by DateTime" part.&lt;/P&gt;&lt;P&gt;You simply do&lt;/P&gt;&lt;PRE&gt;| timechart span=1h count&lt;/PRE&gt;&lt;P&gt;And only _then_ you format your time to the way you want to display it. For example&lt;/P&gt;&lt;PRE&gt;| fieldformat _time=strfile(_time,"%H")&lt;/PRE&gt;</description>
      <pubDate>Tue, 05 Dec 2023 13:11:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670819#M54899</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-12-05T13:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Time Spans</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670836#M54902</link>
      <description>&lt;P&gt;Hi, I tried your solution but it didn't work. How do I modify the query to get the desired output.&lt;/P&gt;&lt;P&gt;for below Query&lt;/P&gt;&lt;P&gt;index="app_cleo_db"&amp;nbsp;&lt;BR /&gt;origname="GEAC_Payroll*"&amp;nbsp;&lt;BR /&gt;| rex "\sorigname=\"GEAC_Payroll\((?&amp;lt;digits&amp;gt;\d+)\)\d{8}_\d{6}\.xml\""&lt;BR /&gt;| search origname="*.xml"&lt;BR /&gt;| eval Date = strftime(_time, "%Y-%m-%d %H:00:00")&lt;BR /&gt;| eval DateOnly = strftime(_time, "%Y-%m-%d")&lt;BR /&gt;| transaction DateOnly, origname&lt;BR /&gt;| timechart span=1h count by DateOnly&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am getting below output&lt;/P&gt;&lt;P&gt;time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2023-12-02  2023-12-03&lt;BR /&gt;2023-12-02 00:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 01:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 02:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 03:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 04:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 05:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 06:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 07:00  1   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 08:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 09:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 10:00  2   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 11:00  1   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 12:00  1   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 13:00  1   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 14:00  3   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 15:00  4   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 16:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 17:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 18:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 19:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 20:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 21:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 22:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-02 23:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-03 00:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-03 01:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-03 02:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-03 03:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-03 04:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;BR /&gt;2023-12-03 05:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&lt;BR /&gt;2023-12-03 06:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 202&lt;BR /&gt;2023-12-03 07:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 52&lt;BR /&gt;2023-12-03 08:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 141&lt;BR /&gt;2023-12-03 09:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 188&lt;BR /&gt;2023-12-03 10:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 256&lt;BR /&gt;2023-12-03 11:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 185&lt;BR /&gt;2023-12-03 12:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 121&lt;BR /&gt;2023-12-03 13:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 52&lt;BR /&gt;2023-12-03 14:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&lt;BR /&gt;2023-12-03 15:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9&lt;BR /&gt;2023-12-03 16:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-03 17:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-03 18:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-03 19:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-03 20:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-03 21:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-03 22:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;2023-12-03 23:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;but i want like below output like this where the 00:00 to 23:00 is stable&lt;/P&gt;&lt;P&gt;time&amp;nbsp;&amp;nbsp; 2023-12-02  2023-12-03&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;00:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;01:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;02:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;03:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;04:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;BR /&gt;05:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&lt;BR /&gt;06:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 202&lt;BR /&gt;07:00  1   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 52&lt;BR /&gt;08:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 141&lt;BR /&gt;09:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 188&lt;BR /&gt;10:00  2   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 256&lt;BR /&gt;11:00  1   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 185&lt;BR /&gt;12:00  1   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 121&lt;BR /&gt;13:00  1   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 52&lt;BR /&gt;14:00  3   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&lt;BR /&gt;15:00  4   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9&lt;BR /&gt;16:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;17:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;18:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;19:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;20:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;21:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;22:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;23:00  0   &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 14:08:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670836#M54902</guid>
      <dc:creator>sujata_nandi</dc:creator>
      <dc:date>2023-12-05T14:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Time Spans</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670840#M54903</link>
      <description>&lt;P&gt;Again - don't use the "by DateTime" clause.&lt;/P&gt;&lt;P&gt;Do a normal timechart and then - if you want to wrap it by day, use the timewrap command.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 14:15:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670840#M54903</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-12-05T14:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Time Spans</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670879#M54906</link>
      <description>&lt;P&gt;I removed the&amp;nbsp;&lt;SPAN&gt;"by DateTime" clause and used the timewrap clause, it is giving me the output for last 24 hours correctly however I only receive files on the weekends and if I try to use this command then it's giving me too many unwanted fields with no values.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 16:18:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670879#M54906</guid>
      <dc:creator>sujata_nandi</dc:creator>
      <dc:date>2023-12-05T16:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Time Spans</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670969#M54921</link>
      <description>&lt;P&gt;You can do&lt;/P&gt;&lt;PRE&gt;| timechart span=1h count&lt;BR /&gt;| where count&amp;gt;0&lt;BR /&gt;| timewrap 1day&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;To filter out "empty" results.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 09:14:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/670969#M54921</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-12-06T09:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Time Spans</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/671009#M54928</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thank you very much for your help. Below is the final query and it is giving me the required output, however I am not able to open the events on a separate tab.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="app_cleo_db"
origname="GEAC_Payroll*"
| rex "\sorigname=\"GEAC_Payroll\((?&amp;lt;digits&amp;gt;\d+)\)\d{8}_\d{6}\.xml\""
| search origname="*.xml"
| eval Date = strftime(_time, "%Y-%m-%d %H:00:00")
| eval DateOnly = strftime(_time, "%Y-%m-%d")
| transaction DateOnly, origname
| timechart span=1h count
| where count&amp;gt;0
| timewrap series=exact time_format="%d-%m-%Y" 1day
| eval _time=strftime(_time, "%H:%M:%S")
| sort _time&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 13:03:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Time-Spans/m-p/671009#M54928</guid>
      <dc:creator>sujata_nandi</dc:creator>
      <dc:date>2023-12-06T13:03:52Z</dc:date>
    </item>
  </channel>
</rss>

