So I want use bucket to group my data by weeks that start on Mondays if I change my query to use earliest=-1w@w1 latest=@w1 Then bucket span=week does the right thing. But I'm going to be running a daily (or hourly) summary index, that I want to bucket by weeks including the current week in progress.
Index:
sourcetype="source" | bucket _time span=day | stats count by severity, customer, _time
Search that works for daily counts
search severity > 9 customer="name" | eval Day=strftime(_time, "%Y-%m-%d")| eval n="count" | xyseries Day, n, count
I need a search that works for weekly counts snapped to mondays.
... View more