Splunk Search
Highlighted

Splunk last 7 days within current month?

Builder

Hello,

I'm using dd/mm/yyyy date format and results are not correctly sorted if we are dealing with data across months.

I've tried https://answers.splunk.com/answers/215005/sorting-date-1.html but it doesn't work. The only right way is to use %Y/%m/%d

Otherwise, is it possible to limit the results to the current month?
alt text
Snapshot attached.

Thanks.

0 Karma
Highlighted

Re: Splunk last 7 days within current month?

Ultra Champion

You should sort by _time and not by the alphanumeric date field.

0 Karma
Highlighted

Re: Splunk last 7 days within current month?

Legend

Try this instead

index=* | rex ... | rex ... | where ... | timechart span=1d count as visits | eval Date=strftime(_time, "%d/%m/%Y") | fields - _time

And if you only want first 7, you can either filter the data to return only the days you want or add head 7 OR tail 7 to the end

View solution in original post

Highlighted

Re: Splunk last 7 days within current month?

Builder

Thanks, it works with timechart.

0 Karma