Hi Splunk Experts, The timewrap command is using d(24 hr) format, but I'm wondering is it possible to make it Today format. Ex: If Current time is 10AM, then it's displaying timechart of 12 AM ...
See more...
Hi Splunk Experts, The timewrap command is using d(24 hr) format, but I'm wondering is it possible to make it Today format. Ex: If Current time is 10AM, then it's displaying timechart of 12 AM to 10AM (12, 14, 16, 18, 20, 22, 00, 02, 04, 06, 08, 10), but I'm looking for 00 AM to 22 (00, 02, 04, 06, 08, 10, 12, 14, 16, 18, 20, 22). Any advice would be much appreciated. index="_internal" error
| timechart span=10m count as Counts
| timewrap d series=exact time_format="%Y-%m-%d"