I am trying to re-format the x-axis time to read cleaner. Here is my spl:
index="servers" source="/var/log/secure" action=failure
| timechart count
| eval time=_time
|table time count
| fieldformat time=strftime(time, "%Y%m%d%H%M")
How can I get it in a format like %Y-%m-%d %H:%M ?
fieldformat should be all you need.
index="servers" source="/var/log/secure" action=failure | timechart count | fieldformat _time=strftime(_time, "%Y-%m-%d %H:%M")
It works for me, but the format of _time changes only in the
timechart output - not in the visualization. The viz appears to be fixed.
I don't know where "_span" is coming from. On my system it's "_time".
You can turn off the x-axis label, by the way. Click the format icon on the viz and there will be options to control the x-axis, y-axis, legend, and other settings.