All Apps and Add-ons

Timewrap monthly delineation?

davidpaper
Contributor

It appears that the timewrap (v1.6) thinks each month is 30 days.

Not every month is 30 days.

Any chance of this getting updated so month lengths are correct by the month?

Tags (1)
1 Solution

carasso
Splunk Employee
Splunk Employee

When you specify "3m" it does indeed use 90 days, for example.

I'm not convinced this is a bug.

The problem is -- supposing I used the length of the last month -- what do you want to do with that knowledge, how do you want to timewrap things? In other words, if you compare January to February, what do you want it to do? If you can answer that, I can change the behavior.

In the meantime, use weeks or days, which are fixed and well defined. (e.g. 4w or 28d)

View solution in original post

carasso
Splunk Employee
Splunk Employee

When you specify "3m" it does indeed use 90 days, for example.

I'm not convinced this is a bug.

The problem is -- supposing I used the length of the last month -- what do you want to do with that knowledge, how do you want to timewrap things? In other words, if you compare January to February, what do you want it to do? If you can answer that, I can change the behavior.

In the meantime, use weeks or days, which are fixed and well defined. (e.g. 4w or 28d)

davidpaper
Contributor

I'm not sure it is a bug either. A month averages 30 days, but if you are trying to compare calendar months, then there should be no expectation that they are always going to be equal. Comparing Jan to Feb has to come with understanding that one month is usually 3 days longer than the other, except when it's 2 days longer.

Maybe m=month (30 day variety) and r=real length month, which the length of the month varies by the month itself (Jan = 31, Feb 28 or 29, with calendar math involved to determine which), Mar = 31, et al).

12m = 360 days, 12r = 365/366 days depending on the year?

Crazy?

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...