Splunk Search

How can I change the legend values for timechart to a different format?

desi_stoitsova
Engager

How can I change the values in the legend for a timechart? I use:
index=indexone sourcetype=sourceone | timechart count by X usenull=0 span=1h |timewrap 1day

Some of the results look like: X_22days_before. I want to have just the X.

Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...