I'm trying to list out all dates between my time picker and have that as a column in my table. I do both things individually but just not together 🙂
| rex "jobID (?<jobid>\d+)"
| rex "dayID (?<dayid>\d+)"
| eval daydt=strptime(dayid, "%Y%m%d")
| eval daydt=strftime(daydt,"%Y-%m-%d")
| transaction jobid dayid endswith="data consumed for jobID"
| eval status=if(closed_txn=="0","Complete","Incomplete")
[ |gentimes start=-1|addinfo|eval date=strftime(mvrange(info_min_time,info_max_time,"1d"),"%F")|mvexpand date
| sort -date
| table date closed_txn daydt _time duration
Can someone tell me whats wrong here?
Should this "day column" go on a row of its own? What if you have more than one data rows for a particular day?
Maybe you want to have a look at the "bin" command (https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Bin) to group your events by day with a "span=1d" parameter.