When I put "sourcetype="splunk_member_info2" | timechart count" on SEARCH,
the result shows monthly result. (Log is collected for about 5 years.)
I want to see the daily result.
is it possible?
try with
"sourcetype="splunk_member_info2" | timechart span=1d count"
View solution in original post
sorry, I wasn't meaning this.
Thank you so much!!
use |chart count by date_mday