Hello,
I'm using dd/mm/yyyy date format and results are not correctly sorted if we are dealing with data across months.
I've tried https://answers.splunk.com/answers/215005/sorting-date-1.html but it doesn't work. The only right way is to use %Y/%m/%d
Otherwise, is it possible to limit the results to the current month?
Snapshot attached.
Thanks.
Try this instead
index=* | rex ... | rex ... | where ... | timechart span=1d count as visits | eval Date=strftime(_time, "%d/%m/%Y") | fields - _time
And if you only want first 7, you can either filter the data to return only the days you want or add head 7
OR tail 7
to the end
Try this instead
index=* | rex ... | rex ... | where ... | timechart span=1d count as visits | eval Date=strftime(_time, "%d/%m/%Y") | fields - _time
And if you only want first 7, you can either filter the data to return only the days you want or add head 7
OR tail 7
to the end
Thanks, it works with timechart.
You should sort by _time
and not by the alphanumeric date field.