Splunk Search

Splunk last 7 days within current month?

splunkreal
Motivator

Hello,

I'm using dd/mm/yyyy date format and results are not correctly sorted if we are dealing with data across months.

I've tried https://answers.splunk.com/answers/215005/sorting-date-1.html but it doesn't work. The only right way is to use %Y/%m/%d

Otherwise, is it possible to limit the results to the current month?
alt text
Snapshot attached.

Thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

sundareshr
Legend

Try this instead

index=* | rex ... | rex ... | where ... | timechart span=1d count as visits | eval Date=strftime(_time, "%d/%m/%Y") | fields - _time

And if you only want first 7, you can either filter the data to return only the days you want or add head 7 OR tail 7 to the end

View solution in original post

sundareshr
Legend

Try this instead

index=* | rex ... | rex ... | where ... | timechart span=1d count as visits | eval Date=strftime(_time, "%d/%m/%Y") | fields - _time

And if you only want first 7, you can either filter the data to return only the days you want or add head 7 OR tail 7 to the end

splunkreal
Motivator

Thanks, it works with timechart.

* If this helps, please upvote or accept solution if it solved *
0 Karma

ddrillic
Ultra Champion

You should sort by _time and not by the alphanumeric date field.

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...