Splunk Search

How to display the max value per day

faribole
Path Finder

My search calculate the number of events of a field per hour per day.
In my chart result I only want to see the max of each day

mysearch | timechart count span=1h as nb | eval Day=strftime(_time,"%Y/%m/%d") | dedup nb | top 1 nb by Day | sort + Day | table Day nb

The result is like that

Day nb
2019-08-26 300
2019-08-27 252
2019-08-28 354
2019-08-29 458

but i would like to see the time slot in my result, like that

Day nb
2019-08-26 10:00:00 300
2019-08-27 15:00:00 252
2019-08-28 13:00:00 354
2019-08-29 11:00:00 458

How to do that ?
Thanks

Tags (2)
0 Karma
1 Solution

DalJeanis
Legend

Try this -

mysearch 
| timechart span=1h  count as nb 
| eval Day=strftime(_time,"%Y/%m/%d") 
| eval Hour=strftime(_time,"%H:%M") 
| sort 0 Day - nb
| dedup Day 
| table Day Hour nb

View solution in original post

faribole
Path Finder

Thanks a lot. It's ok

0 Karma

DalJeanis
Legend

Try this -

mysearch 
| timechart span=1h  count as nb 
| eval Day=strftime(_time,"%Y/%m/%d") 
| eval Hour=strftime(_time,"%H:%M") 
| sort 0 Day - nb
| dedup Day 
| table Day Hour nb
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...