Reporting

Split a Report in Weeks

Oti47
Path Finder

Hello,
I'd like to split a Report in Weeks.
I use a time chart report with span=1week, but the y-axis display the first day of a week.

XXX | timechart span=1week sum(NWert) AS Umsatz

How could i change the display of the x-axis in Weeks like this 22, 23, 24, 25?

Thanks
Oti

Tags (1)
1 Solution

echalex
Builder

Hi Oti47,

Rather than using timechart, use chart by week. You'll get the weeknumber from strftime:

XXX | eval week=strftime(_time,"%V") |chart sum(NWert) AS umsatz by week

HTH,

View solution in original post

echalex
Builder

Glad it worked. Feel free to accept the answer as the correct one, so others can see it's solved.

0 Karma

Oti47
Path Finder

Thanks.

Works for me.

0 Karma

echalex
Builder

Hi Oti47,

Rather than using timechart, use chart by week. You'll get the weeknumber from strftime:

XXX | eval week=strftime(_time,"%V") |chart sum(NWert) AS umsatz by week

HTH,

echalex
Builder

Note!

This works for the ISO 8601 standard, where a week starts on Monday and the first week of the year is the first to have at least four days of the new year in it. Iow. if 1st Jan is on a Friday, its week number is 53 of the last week.

Users who would like to have the week starting on a Sunday, should consider using %U rather than %V.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...