All Apps and Add-ons

Timewrap monthly delineation?

davidpaper
Contributor

It appears that the timewrap (v1.6) thinks each month is 30 days.

Not every month is 30 days.

Any chance of this getting updated so month lengths are correct by the month?

Tags (1)
1 Solution

carasso
Splunk Employee
Splunk Employee

When you specify "3m" it does indeed use 90 days, for example.

I'm not convinced this is a bug.

The problem is -- supposing I used the length of the last month -- what do you want to do with that knowledge, how do you want to timewrap things? In other words, if you compare January to February, what do you want it to do? If you can answer that, I can change the behavior.

In the meantime, use weeks or days, which are fixed and well defined. (e.g. 4w or 28d)

View solution in original post

carasso
Splunk Employee
Splunk Employee

When you specify "3m" it does indeed use 90 days, for example.

I'm not convinced this is a bug.

The problem is -- supposing I used the length of the last month -- what do you want to do with that knowledge, how do you want to timewrap things? In other words, if you compare January to February, what do you want it to do? If you can answer that, I can change the behavior.

In the meantime, use weeks or days, which are fixed and well defined. (e.g. 4w or 28d)

davidpaper
Contributor

I'm not sure it is a bug either. A month averages 30 days, but if you are trying to compare calendar months, then there should be no expectation that they are always going to be equal. Comparing Jan to Feb has to come with understanding that one month is usually 3 days longer than the other, except when it's 2 days longer.

Maybe m=month (30 day variety) and r=real length month, which the length of the month varies by the month itself (Jan = 31, Feb 28 or 29, with calendar math involved to determine which), Mar = 31, et al).

12m = 360 days, 12r = 365/366 days depending on the year?

Crazy?

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...