Hi i have a timechart
| timechart count by serial_number
is there a way to change the use of _time to another date field?
yes, you can use any other field which contains a time information:
| eval _time=MyTime
If MyTime is a text string, you can use strptime to convert the string to time. For example, if the MyTime is "03-22-2013 11:55":
| eval MyTimeDate=strptime(MyTime,"%m-%d-%Y %H:%M") | eval _time=MyTime
Sure. timechart
is, more or less, an alias for bucket _time | chart <functions> over _time
so if you want to use another field, just do
`bucket yourfield | chart <functions> over yourfield`