Splunk Search

In a chart count where days are the column header, how do I get the days to list in chronological order?

rossblassingame
New Member

I'm trying to get a table where "Days" are the column headers (chronologically) and hours are the row headers that show the total events that happened in each hour per day. Something like this:

Sunday | Monday | Tuesday | Wednesday | Thursday | Friday | Saturday
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23

I think I have it mostly working with the following:

[code] | chart count over date_hour by date_wday

However, the days in the row headers are ordered alphabetically, not chronologically. So instead of:
Sunday | Monday | Tuesday | Wednesday | Thursday | Friday | Saturday

What's showing in the chart is:

Friday | Monday | Saturday | Sunday | Thursday | Tuesday | Wednesday

Could anyone please help me figure this out?

Thanks.

Tags (3)
0 Karma
1 Solution

renjith_nair
Legend

@rossblassingame

Try mentioning the headers in the field list like | chart count over date_hour by date_wday|fields Monday,Tuesday ,Wednesday ,Thursday ,Friday,Saturday

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

renjith_nair
Legend

@rossblassingame

Try mentioning the headers in the field list like | chart count over date_hour by date_wday|fields Monday,Tuesday ,Wednesday ,Thursday ,Friday,Saturday

---
What goes around comes around. If it helps, hit it with Karma 🙂

rossblassingame
New Member

Above answer led me to the right answer. What worked for me:

| chart count over date_hour by date_wday | fields date_hour, sunday, monday, tuesday, wednesday, thursday, friday, saturday

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...