<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Modifying x-axis format in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Modifying-x-axis-format/m-p/468327#M131855</link>
    <description>&lt;P&gt;&lt;CODE&gt;fieldformat&lt;/CODE&gt; should be all you need.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="servers" source="/var/log/secure" action=failure
| timechart count
| fieldformat _time=strftime(_time, "%Y-%m-%d %H:%M")
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 02 Jun 2020 14:10:24 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-06-02T14:10:24Z</dc:date>
    <item>
      <title>Modifying x-axis format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modifying-x-axis-format/m-p/468326#M131854</link>
      <description>&lt;P&gt;I am trying to re-format the x-axis time to read cleaner. Here is my spl:&lt;BR /&gt;index="servers" source="/var/log/secure" action=failure&lt;BR /&gt;| timechart count&lt;BR /&gt;| eval time=_time&lt;BR /&gt;|table time count&lt;BR /&gt;| fieldformat time=strftime(time, "%Y%m%d%H%M")&lt;/P&gt;
&lt;P&gt;How can I get it in a format like %Y-%m-%d %H:%M ?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 18:06:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modifying-x-axis-format/m-p/468326#M131854</guid>
      <dc:creator>user789</dc:creator>
      <dc:date>2020-06-08T18:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Modifying x-axis format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modifying-x-axis-format/m-p/468327#M131855</link>
      <description>&lt;P&gt;&lt;CODE&gt;fieldformat&lt;/CODE&gt; should be all you need.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="servers" source="/var/log/secure" action=failure
| timechart count
| fieldformat _time=strftime(_time, "%Y-%m-%d %H:%M")
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 02 Jun 2020 14:10:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modifying-x-axis-format/m-p/468327#M131855</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-02T14:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: Modifying x-axis format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modifying-x-axis-format/m-p/468328#M131856</link>
      <description>&lt;P&gt;When I try this, I don't get any results. &lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 15:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modifying-x-axis-format/m-p/468328#M131856</guid>
      <dc:creator>user789</dc:creator>
      <dc:date>2020-06-02T15:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Modifying x-axis format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modifying-x-axis-format/m-p/468329#M131857</link>
      <description>&lt;P&gt;It works for me, but the format of _time changes only in the &lt;CODE&gt;timechart&lt;/CODE&gt; output - not in the visualization.  The viz appears to be fixed.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 17:15:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modifying-x-axis-format/m-p/468329#M131857</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-02T17:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: Modifying x-axis format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modifying-x-axis-format/m-p/468330#M131858</link>
      <description>&lt;P&gt;With this I get a visualization with count on the bottom, then above that, another x-axis labeled" _span". &lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 18:14:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modifying-x-axis-format/m-p/468330#M131858</guid>
      <dc:creator>user789</dc:creator>
      <dc:date>2020-06-02T18:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: Modifying x-axis format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modifying-x-axis-format/m-p/468331#M131859</link>
      <description>&lt;P&gt;I don't know where "_span" is coming from.  On my system it's "_time". &lt;BR /&gt;
You can turn off the x-axis label, by the way.  Click the format icon on the viz and there will be options to control the x-axis, y-axis, legend, and other settings.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:36:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modifying-x-axis-format/m-p/468331#M131859</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-30T05:36:44Z</dc:date>
    </item>
  </channel>
</rss>

