<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prior day Report on Monday in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Prior-day-Report-on-Monday/m-p/58059#M1253</link>
    <description>&lt;P&gt;Thanks for the lesson and the help&lt;/P&gt;

&lt;P&gt;your a true asset to the Splunk team&lt;/P&gt;

&lt;P&gt;Hope the weather is nice in New Jersey&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2013 20:44:00 GMT</pubDate>
    <dc:creator>hartfoml</dc:creator>
    <dc:date>2013-09-09T20:44:00Z</dc:date>
    <item>
      <title>Prior day Report on Monday</title>
      <link>https://community.splunk.com/t5/Reporting/Prior-day-Report-on-Monday/m-p/58055#M1249</link>
      <description>&lt;P&gt;I have a report that shows me the items installed on my systems for the prior day. the only problem is Monday as no one works on Sunday the report is always blank but should show for all day Friday and Saturday and Sunday.  Mondays report should show for Friday and the weekend&lt;/P&gt;

&lt;P&gt;Can i do this with the same search or do I have to create a new search?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=ea sourcetype="*wineventlog:application" EventCode=11707 OR EventCode=11708 OR EventCode=11728 host!="*dev*" earliest=-1d@d latest=@d 
| eval date_wday = strftime(_time, "%A") 
| dedup _raw 
| rex field=Message "(?s)Product: (?&amp;lt;product_name&amp;gt;.*) --" 
| table _time date_wday host User product_name EventCode 
| eval status=case(EventCode == 11708, "Failed", EventCode == 11707, "Success", EventCode == 11728, "Success") 
| rename _time AS Time host AS Server product_name AS "Product Installed" status AS "Status" 
| convert timeformat="%m/%d/%Y - %H:%M:%S" ctime(Time) 
| fields Time Server User "Product Installed" Status EventCode`
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 09 Sep 2013 16:21:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Prior-day-Report-on-Monday/m-p/58055#M1249</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-09-09T16:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Prior day Report on Monday</title>
      <link>https://community.splunk.com/t5/Reporting/Prior-day-Report-on-Monday/m-p/58056#M1250</link>
      <description>&lt;P&gt;I used a subsearch to populate "earliest" and "latest".&lt;/P&gt;

&lt;P&gt;This works:&lt;/P&gt;

&lt;P&gt;index=main [ search index=_internal | head 1 | eval today=strftime(time(), "%a") | eval earliest=if(today="Mon", "-3d@d", "-1d@d") | eval latest="@d" | return earliest latest ]&lt;/P&gt;

&lt;P&gt;I started here:&lt;/P&gt;

&lt;P&gt;[ | stats count | eval earliest=if(date_wday="monday", "-3d@d", "-1d@d") | eval latest="@d" | table earliest, latest ] &lt;/P&gt;

&lt;P&gt;That includes the tabular subsearch output, so I get a parse error from the search.&lt;/P&gt;

&lt;P&gt;Switch instead to return:&lt;/P&gt;

&lt;P&gt;[ | stats count | eval earliest=if(date_wday="monday", "-3d@d", "-1d@d") | eval latest="@d" | return earliest, latest ] &lt;/P&gt;

&lt;P&gt;From here I can use the search inspector to see what the subsearch evaluates to. It seems that it always comes back as &lt;A href="mailto:-1d@d"&gt;-1d@d&lt;/A&gt;. I think you're right about the context for "date_wday". If I change my | stats to something else "fast", like "search index=_internal | head 1", I do get date_wday, but that would be subject to the time of the one event returned. I think instead we should consider an eval / strptime based approach in relation to "now".&lt;/P&gt;

&lt;P&gt;This is what I used to debug my settings until I had the today condition correct: &lt;/P&gt;

&lt;P&gt;index=_internal | head 1 | eval today=strftime(time(), "%a") | eval earliest=if(today="Mon", "-3d@d", "-1d@d") | eval latest="@d" | table earliest, latest&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2013 17:20:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Prior-day-Report-on-Monday/m-p/58056#M1250</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-09-09T17:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: Prior day Report on Monday</title>
      <link>https://community.splunk.com/t5/Reporting/Prior-day-Report-on-Monday/m-p/58057#M1251</link>
      <description>&lt;P&gt;This sounds like a good suggestion but I am having trouble with where to put it in the search:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;search foo=* | search earliest=if(date_wday="Monday",-3d@d,-1d@d) latest=@d | table foo&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;This doesn't work because there is not time-frame to look for date_wday.&lt;/P&gt;

&lt;P&gt;Maybe something like this;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;search foo= [| search _time | eval earliest=if(date_wday="Monday",-3d@d,-1d@d)] latest=@d | table foo&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2013 18:02:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Prior-day-Report-on-Monday/m-p/58057#M1251</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-09-09T18:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: Prior day Report on Monday</title>
      <link>https://community.splunk.com/t5/Reporting/Prior-day-Report-on-Monday/m-p/58058#M1252</link>
      <description>&lt;P&gt;Edited to provide a working example.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2013 18:39:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Prior-day-Report-on-Monday/m-p/58058#M1252</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-09-09T18:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: Prior day Report on Monday</title>
      <link>https://community.splunk.com/t5/Reporting/Prior-day-Report-on-Monday/m-p/58059#M1253</link>
      <description>&lt;P&gt;Thanks for the lesson and the help&lt;/P&gt;

&lt;P&gt;your a true asset to the Splunk team&lt;/P&gt;

&lt;P&gt;Hope the weather is nice in New Jersey&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2013 20:44:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Prior-day-Report-on-Monday/m-p/58059#M1253</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-09-09T20:44:00Z</dc:date>
    </item>
  </channel>
</rss>

