Splunk Search
Highlighted

Set chart from 12am to 11.59am ? [search queries]

Path Finder

I have this search query sourcetype="CurrentWeatherSGMap" Message="Yishun" | eval Description=case(currentsummary="Rain", "Poor",currentsummary="Thundery Showers","Poor", currentsummary="Cloudy", "Fair", currentsummary="Partly Cloudy", "Excellent") | chart dc(Description) over _time by Description | eval Poor=if(Description==Poor, "1", "1"). How can I set the chart to display from 12am to 12am time range daily ?

Or can I use advanced xml to display my result ?

Tags (3)
0 Karma
Highlighted

Re: Set chart from 12am to 11.59am ? [search queries]

Champion

You can explicitly define earlest=-1d@d latest=0d@d if only the previous day's data is to be displayed.

Highlighted

Re: Set chart from 12am to 11.59am ? [search queries]

Communicator

Hi,

I would suggest using the following in your search.

earliest=@d latest=@d+12

let me know if that works for you.

Regards,
Amit Saxena

View solution in original post

0 Karma
Highlighted

Re: Set chart from 12am to 11.59am ? [search queries]

Communicator

Hi,
Do confirm it the above solution worked for you ?
Regards,
Amit Saxena

0 Karma