Splunk Search

timechart day of week

ewanbrown
Path Finder

Hi,

I have a report which is a basic timechart, but in the output like to put the day of week as well as the day

So Monday 8 December

rather than

8 December

Is this possible?

Thanks

0 Karma

chimell
Motivator
    Try your search code like this : 

 your search here .... | convert timeformat="%A %d %B " ctime(_time) AS c_time |chart count by c_time

    it will give you the date format that you want. E.g : Monday 10 february  in X-Axis 
0 Karma

somesoni2
Revered Legend

aholzer
Motivator

You can use the convert command. Select from these options the proper format you wish the date to show up in. Here's an example:

your search here... | convert timeformat="%A %d %B" ctime(_time)

This should result in changing the _time field to strings of the format: ["Full weekday name" "numerical Day of the month" "Full month name"], example: "Monday 08 December".

Hope this helps

Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...