Splunk Search

How to create a search on charting time?

lekshmi279
New Member

I have some users with shift timings (Start and End time in a lookup file). How can I use Splunk to chart their availability? More precisely, I want each user to be in the Y axis and X axis shows time. I want a bar chart showing each of their availability based on their start and end time.
(First time user of Splunk)

0 Karma

nickhills
Ultra Champion

Take a look at this post which describes how to show similar (vacation) data on a calendar view.
https://answers.splunk.com/answers/730878/mark-all-days-from-start-date-to-end-date-as-vacat.html
https://answers.splunk.com/answers/713033/can-we-create-a-vacation-tracker-in-splunk.html

If my comment helps, please give it a thumbs up!
0 Karma

lekshmi279
New Member

Hey @nickhillscpl
Take a loo at which post?

0 Karma

nickhills
Ultra Champion

whoops - sorry! Must have been a copy/paste fail!

If my comment helps, please give it a thumbs up!
0 Karma

lekshmi279
New Member

@nickhillscpl Thank you for your input!
Your solution may not come in as handy for me. I'm looking for a shift schedule format. The examples you gave me were more of handling dates. I want to chart time. Specifically, in 24 hours, I want to mark employees' availability (say from 9AM to 6PM).
Can you help me with that?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...