Splunk Search

Search weekday during time, and include all weekend days

Cmiddleton-oppd
Explorer

Hello, 
my current search is 

index=winsec source=WinEventLog:Security EventCode=6272 
| eval date_hour = strftime(_time, "%H")
| where date_hour >= 19 OR date_hour <=06
| timechart count(src_user)


This provides me with a graph of logins made after hours. I want to expand the acceptable items to include the entire days of saturday/sunday as well. When I attempt to add this, i get "no results" what would be the best way to include that? 

Labels (2)
Tags (3)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Extract and test for the day of the week similar to how date_hour was done.

index=winsec source=WinEventLog:Security EventCode=6272 
| eval date_hour = strftime(_time, "%H"), date_wday = strftime(_time, "%A")
| where date_hour >= 19 OR date_hour <=06 OR date_wday = "Saturday" OR date_wday = "Sunday"
| timechart count(src_user)
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Extract and test for the day of the week similar to how date_hour was done.

index=winsec source=WinEventLog:Security EventCode=6272 
| eval date_hour = strftime(_time, "%H"), date_wday = strftime(_time, "%A")
| where date_hour >= 19 OR date_hour <=06 OR date_wday = "Saturday" OR date_wday = "Sunday"
| timechart count(src_user)
---
If this reply helps you, Karma would be appreciated.

Cmiddleton-oppd
Explorer

I think this would work perfectly, but the system does not appear to have date_wday enabled. Using this term always provides me with " no results" 

0 Karma

glc_slash_it
Path Finder

The date_wday is being created with the eval command on the second line...

I'll break it down for you.

| eval date_hour = strftime(_time, "%H")
| eval date_wday = strftime(_time, "%A")

 

Cmiddleton-oppd
Explorer

You're right! my mistake, I didn't read the entire query.

Thanks for pointing out my mistake!

Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...