Hi,
I created a column chart in Splunk that shows month but will like to also indicate the day of the week for each of those months
Sample query
-------------------
index=_internal
| bucket _time span =1d
|eval month=strftime(_time,"%b")
| eval day=strftime(_time,"%a")
| stats avg(count) as Count max(count) as maximum by month, day
The issue is the graph shows month on the x axis and I want it to indicate both month and day of the week
Hi @Strangertinz ,
please try this:
index=_internal
| bucket _time span =1d
| eval date=strftime(_time,"%a-%b")
| stats avg(count) as Count max(count) as maximum by date
Ciao.
Giuseppe
Thanks for your quick response but the query is not working
Hi @Strangertinz ,
sorry but what do you want to calculate with avg(count) and max(count)?
count isn't a field to calculate average or maximun.
you can have the count of events by period
index=_internal
| bucket _time span =1d
| eval date=strftime(_time,"%a-%b")
| stats count by date
Ciao.
Giuseppe
I want to calculate average count per day and maximum count per month. Like all the Mondays , Tuesdays of a given month combined and averaged