got a date extracted from a file name and got the count of files received on for that extracted date.
date-2016-03-28 extracted from the files received at a specific location.
/ubidata/axway/JourneyData/AAA_NA_70_2016-03-28-00-47-08_353466071286872_1HGCR2F5XDA159398_0_0.zip
Now we want a time chart to show the count of extracted date(2016-03-28) on that date.
The default timechart shows values by system time. Want to use the extracted date as the xaxis date and showing the timechart trend for those counts.
Thanks.
Convert your date to an epoch timestamp, and eval it to _time:
... | eval _time = strptime(file_date, "%F") | timechart dc(source)
Hi @Jeremiah
Thanks for the update, we see an notification under the job tab :
Some events were removed by Timeliner because they were missing _time[p01apl385.ent.com] Some events were removed by Timeliner because they were missing _time
is there something which needs to be modified.
Thanks.
Your regex to create file_date
is probably buggy. Try this to find broken events and enhance your field extraction:
... | where isnull(file_date)