Getting Data In

How to change week to time format?

hagar71
Explorer

hello everyone,

I have a column which contains week1 , week2 ,week3,week4,week5 and I want an input to the chart to show me the data from week1 to week3 for example or week2 to week5 how could I do that? 

Labels (3)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

If you want a filter to only show weekX to weekY in your chart, you can use one or two text input boxes do define start/end week numbers. Let's assume you have 2 inputs, with the tokens tok_week_start and tok_week_end, then in your search you can finish the search with something like this

... your chart building search ...
| rex field=week_column "week(?<week_no>\s+)"
| where week_no>=$tok_week_start$ AND week_no<=$tok_week_end$
| fields - week_no

 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

You can of course do this with a time picker input, but that will not be a week based approach.

I assume you were talking about a dashboard and my comments were related to the classic dashboard use of tokens.

0 Karma

hagar71
Explorer

@bowesmana 

I tried 

| rex field=Date "week(?<week_no>\s+)"
| where week_no>="week1" AND week_no<="week5"
| fields - week_no

but No results found the column of the weeks called Date 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Should be

| rex field=Date "week\s?(?<week_no>\d+)"
| where week_no>=1 AND week_no<=5
| fields - week_no

regex was wrong in my first example.

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...