I have a collection of log data in an index and for the purposes of this discussion _time has the value I want. When I do:
index="my_index" | timechart count span=7d
The resultant visualization always seems to start on a Thursday. I would like it to start on a Sunday. Is there a way to do this?
try this ,
index="my_index" | eval Day1ofWeek = strftime(relative_time(_time,"@w0"),"%m/%d") | chart count by Day1ofWeek
try this ,
index="my_index" | eval Day1ofWeek = strftime(relative_time(_time,"@w0"),"%m/%d") | chart count by Day1ofWeek
Sabbadri,
This definitely appears to work, but can you help understand why? More specifically where did you find the definition of @w0 in the relative_time function?
Secondary question...
Is there anyway to force this value back into _time so one can use single value visualizations?
EDIT:
Nevermind.... I figured this part out!
Do like this
index="my_index" | eval _time=relative_time(_time,"@w0") | chart count by _time
please check below link,
http://docs.splunk.com/Documentation/Splunk/6.6.2/Search/Specifytimemodifiersinyoursearch
Topic: Examples of relative time modifiers
Thanks much!!!
Try | timechart span=1w count
Somesoni2,
This yields the same result, unfortunately.