Hi Splunkers,
I am looking for a query to categorize timestamp into Morning, Afternoon, Night. I'm using this to know how many items were seen for each category in a month
0001-0800 = Morning
0801-1600 = Afternoon
1601-0000 = Night
Example output:
Date Time Category
02-May-2023 1043 Afternoon
02-May-2023 1932 Night
04-May-2023 0249 Morning
04-May-2023 0717 Morning
14-May-2023 2051 Night
20-May-2023 0534 Morning
Thank you very much
| bin _time span=8h aligntime=@d