Hi all,
I am using the timechart graph to represent number of apples every week over last 28 days and compare it to previous other weeks using timewrap command , The problem here is i see that the latest dates and weekdays (Eg:Sun Jun 10) are visible on xaxis. Is there any possiblity that i get on week days (Eg: Sun) instead of date??
Any help on this would be much appreciated.
Thanks,
Swathi
@Veeruswathi, you can try the following run anywhere search.
index=_internal sourcetype=splunkd log_level!=INFO earliest=-28d@d latest=now
| timechart span=1d count as ERROR
| timewrap 1w
| eval Time=strftime(_time,"%a")
| field - _*
| table Time *
_time field is removed and retained columns are Time (as first column) followed by other fields created by timechart followed by timewrap commands.
something like this?index="_audit" | timechart count | eval time=strftime(_time, "%a") | fields time,count | fields - _time
I am not clear on your requirements but use this code as it is(sine this runs on the default _audit index it will give an output for you as well), the x axis will come only as day names. I do not understand however how just having the day names help you in this case, however that is your use case
Any help on this would be much appreciated