We have time-chart visualization on a dashboard. The events are uploaded manually on last day of every month with timestamp of last day of month.
Tool tip, when hovered over the line chart visualization shows date as first day of the month with format MMM D, YYYY
I would like to format the date to show either date that the source has been indexed with or show only Month and Year.
Please provide me your suggestions on how this can be achieved.
I am currently using "timechart span=1mon". This shows 1st day of month in Tool tip.
I am getting following for your search,
MyTime: 2020-03-31 23:30:00.000
MyIndexTime = 2020-04-01 12:45:10.000
To give more info on how i upload data,
- I get a monthly report (xls) on first day of next month. March report is generated on 1st of April.
- Using "TIMESTAMP_FIELDS" in sourcetype, i have configured a column name 'timestamp' from which splunk needs to fetch timestamp during indexing. This is what we see in 'MyTime'
- In the xls i want to index, i add a column 'timestamp' and fill in last day of month and upload this file to splunk. 'MyIndexTime' is showing date on which i have uploaded the data.