Splunk Search

Splunk last 7 days within current month?

splunkreal
Motivator

Hello,

I'm using dd/mm/yyyy date format and results are not correctly sorted if we are dealing with data across months.

I've tried https://answers.splunk.com/answers/215005/sorting-date-1.html but it doesn't work. The only right way is to use %Y/%m/%d

Otherwise, is it possible to limit the results to the current month?
alt text
Snapshot attached.

Thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

sundareshr
Legend

Try this instead

index=* | rex ... | rex ... | where ... | timechart span=1d count as visits | eval Date=strftime(_time, "%d/%m/%Y") | fields - _time

And if you only want first 7, you can either filter the data to return only the days you want or add head 7 OR tail 7 to the end

View solution in original post

sundareshr
Legend

Try this instead

index=* | rex ... | rex ... | where ... | timechart span=1d count as visits | eval Date=strftime(_time, "%d/%m/%Y") | fields - _time

And if you only want first 7, you can either filter the data to return only the days you want or add head 7 OR tail 7 to the end

splunkreal
Motivator

Thanks, it works with timechart.

* If this helps, please upvote or accept solution if it solved *
0 Karma

ddrillic
Ultra Champion

You should sort by _time and not by the alphanumeric date field.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...