Splunk Search

Formatting Timechart to sort by weekly sums, not per day

nce054
Path Finder

I am working on a timechart, and I want it to display the sums for each week, instead of each day. Does anyone know how to do this?

Thanks

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

You need to add (or change if it is span=1d) span=1w and get rid of any per* parameters after the timechart command.

View solution in original post

0 Karma

woodcock
Esteemed Legend

You need to add (or change if it is span=1d) span=1w and get rid of any per* parameters after the timechart command.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Do you want to change the sorting or to change the span your timechart calculates sums over?

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...