Splunk Search

timechart day of week

ewanbrown
Path Finder

Hi,

I have a report which is a basic timechart, but in the output like to put the day of week as well as the day

So Monday 8 December

rather than

8 December

Is this possible?

Thanks

0 Karma

chimell
Motivator
    Try your search code like this : 

 your search here .... | convert timeformat="%A %d %B " ctime(_time) AS c_time |chart count by c_time

    it will give you the date format that you want. E.g : Monday 10 february  in X-Axis 
0 Karma

somesoni2
Revered Legend

aholzer
Motivator

You can use the convert command. Select from these options the proper format you wish the date to show up in. Here's an example:

your search here... | convert timeformat="%A %d %B" ctime(_time)

This should result in changing the _time field to strings of the format: ["Full weekday name" "numerical Day of the month" "Full month name"], example: "Monday 08 December".

Hope this helps

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...