Splunk Search

timechart day of week

ewanbrown
Path Finder

Hi,

I have a report which is a basic timechart, but in the output like to put the day of week as well as the day

So Monday 8 December

rather than

8 December

Is this possible?

Thanks

0 Karma

chimell
Motivator
    Try your search code like this : 

 your search here .... | convert timeformat="%A %d %B " ctime(_time) AS c_time |chart count by c_time

    it will give you the date format that you want. E.g : Monday 10 february  in X-Axis 
0 Karma

somesoni2
Revered Legend

aholzer
Motivator

You can use the convert command. Select from these options the proper format you wish the date to show up in. Here's an example:

your search here... | convert timeformat="%A %d %B" ctime(_time)

This should result in changing the _time field to strings of the format: ["Full weekday name" "numerical Day of the month" "Full month name"], example: "Monday 08 December".

Hope this helps

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...