See the 'series=exact' and time_format option in the documentation
| timewrap series=exact time_format="%d-%m-%Y" 1d
It's not clear what you are asking - do you have a problem using the timewrap command?
The documentation gives examples of how to use timewrap
https://docs.splunk.com/Documentation/Splunk/8.2.7/SearchReference/Timewrap
What sort of visualisation do you want?
Suppose think my query is in this way.
index=temp "error" earliest=-3d@d latest=now|timechart count|timewrap d
Result:
I will be showing the count in line chart. Where it list down the peaks of error count with respect to 24hrs of time and in the right side it will show options to select the 1dayago data,2dataago,3 days ago..
So my question is, there is any way to show the date rather than showing date like this 1dayago data,2dataago,3 days ago. I was expecting date like this, Example today is 09-11-2022, so the data on right side of line chart will be 08-11-2022, 07-11-2022, 06-11-2022..
That's it.
See the 'series=exact' and time_format option in the documentation
| timewrap series=exact time_format="%d-%m-%Y" 1d