Splunk Search

How to split time into 3 shifts with labels on x-axis?

dzyfer
Path Finder

Hi, I have a timechart that is currently split into 8-hour shift bins, however as it is a timechart, the x-axis only shows the timestamps, while I would like the bins to be labeled by their shifts.

Sample data:

Count | Time | Shift

500 | 0700 (Yesterday) | Shift A

750 | 1500 (Yesterday) | Shift B

500 | 2300 (Yesterday) | Shift C

700 | 0700 (Today) | Shift A

600 | 1500 (Today) | Shift B

 

One tricky part is that "Shift C" overlaps between 2 dates as well.
Any ideas on how to define the time range for the shifts, then split and label the bins by their shifts would be greatly appreciated. Thanks!

Labels (7)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| table shift count
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...