Splunk Search

Formatting Timechart to sort by weekly sums, not per day

nce054
Path Finder

I am working on a timechart, and I want it to display the sums for each week, instead of each day. Does anyone know how to do this?

Thanks

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

You need to add (or change if it is span=1d) span=1w and get rid of any per* parameters after the timechart command.

View solution in original post

0 Karma

woodcock
Esteemed Legend

You need to add (or change if it is span=1d) span=1w and get rid of any per* parameters after the timechart command.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Do you want to change the sorting or to change the span your timechart calculates sums over?

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...