Getting Data In

How to change week to time format?

hagar71
Explorer

hello everyone,

I have a column which contains week1 , week2 ,week3,week4,week5 and I want an input to the chart to show me the data from week1 to week3 for example or week2 to week5 how could I do that? 

Labels (3)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

If you want a filter to only show weekX to weekY in your chart, you can use one or two text input boxes do define start/end week numbers. Let's assume you have 2 inputs, with the tokens tok_week_start and tok_week_end, then in your search you can finish the search with something like this

... your chart building search ...
| rex field=week_column "week(?<week_no>\s+)"
| where week_no>=$tok_week_start$ AND week_no<=$tok_week_end$
| fields - week_no

 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

You can of course do this with a time picker input, but that will not be a week based approach.

I assume you were talking about a dashboard and my comments were related to the classic dashboard use of tokens.

0 Karma

hagar71
Explorer

@bowesmana 

I tried 

| rex field=Date "week(?<week_no>\s+)"
| where week_no>="week1" AND week_no<="week5"
| fields - week_no

but No results found the column of the weeks called Date 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Should be

| rex field=Date "week\s?(?<week_no>\d+)"
| where week_no>=1 AND week_no<=5
| fields - week_no

regex was wrong in my first example.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...