How about this... ( it calculates sunday but it may help.)
convert your time field into epochtime (so that splunk can know that its date)
week number (0, sunday - 6, saturday) can be exploited by strftime([epoch time], "%w")
function relative_time(p_date, "-2d@d") gives minus 2day as result. So if you minus week number from original date, you can get the date which week is same but weekday is 0(sunday.)
hope this helps!
source="some_source.csv"
| eval p_date=strptime(date,"%Y/%m/%d %H:%M")
| eval week_num=strftime(p_date,"%w")
| eval week_start_p=relative_time(p_date, "-".created_week_num."d@d")
| eval week_start=strftime(week_start_p, "%m/%d week")
| stats count by created_week_start
... View more