Splunk Search

Splunk last 7 days within current month?

splunkreal
Motivator

Hello,

I'm using dd/mm/yyyy date format and results are not correctly sorted if we are dealing with data across months.

I've tried https://answers.splunk.com/answers/215005/sorting-date-1.html but it doesn't work. The only right way is to use %Y/%m/%d

Otherwise, is it possible to limit the results to the current month?
alt text
Snapshot attached.

Thanks.

* If this helps, please upvote or accept solution 🙂 *
0 Karma
1 Solution

sundareshr
Legend

Try this instead

index=* | rex ... | rex ... | where ... | timechart span=1d count as visits | eval Date=strftime(_time, "%d/%m/%Y") | fields - _time

And if you only want first 7, you can either filter the data to return only the days you want or add head 7 OR tail 7 to the end

View solution in original post

sundareshr
Legend

Try this instead

index=* | rex ... | rex ... | where ... | timechart span=1d count as visits | eval Date=strftime(_time, "%d/%m/%Y") | fields - _time

And if you only want first 7, you can either filter the data to return only the days you want or add head 7 OR tail 7 to the end

splunkreal
Motivator

Thanks, it works with timechart.

* If this helps, please upvote or accept solution 🙂 *
0 Karma

ddrillic
Ultra Champion

You should sort by _time and not by the alphanumeric date field.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...