All Apps and Add-ons

Timewrap monthly delineation?

davidpaper
Contributor

It appears that the timewrap (v1.6) thinks each month is 30 days.

Not every month is 30 days.

Any chance of this getting updated so month lengths are correct by the month?

Tags (1)
1 Solution

carasso
Splunk Employee
Splunk Employee

When you specify "3m" it does indeed use 90 days, for example.

I'm not convinced this is a bug.

The problem is -- supposing I used the length of the last month -- what do you want to do with that knowledge, how do you want to timewrap things? In other words, if you compare January to February, what do you want it to do? If you can answer that, I can change the behavior.

In the meantime, use weeks or days, which are fixed and well defined. (e.g. 4w or 28d)

View solution in original post

carasso
Splunk Employee
Splunk Employee

When you specify "3m" it does indeed use 90 days, for example.

I'm not convinced this is a bug.

The problem is -- supposing I used the length of the last month -- what do you want to do with that knowledge, how do you want to timewrap things? In other words, if you compare January to February, what do you want it to do? If you can answer that, I can change the behavior.

In the meantime, use weeks or days, which are fixed and well defined. (e.g. 4w or 28d)

davidpaper
Contributor

I'm not sure it is a bug either. A month averages 30 days, but if you are trying to compare calendar months, then there should be no expectation that they are always going to be equal. Comparing Jan to Feb has to come with understanding that one month is usually 3 days longer than the other, except when it's 2 days longer.

Maybe m=month (30 day variety) and r=real length month, which the length of the month varies by the month itself (Jan = 31, Feb 28 or 29, with calendar math involved to determine which), Mar = 31, et al).

12m = 360 days, 12r = 365/366 days depending on the year?

Crazy?

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...