dayofyear
You can use dayofyear to perform year-over-year comparisons by day, analyze seasonal trends, and track how metrics evolve throughout the year. This is especially useful for time-series analysis where you want to align data across multiple years by day number.
Use it when you want to:
- Compare activity or metrics on the same day across different years.
- Identify seasonal trends and patterns in log, trace, or security data.
- Track progress through the year for cumulative reporting.
Usage#
Syntax#
dayofyear(datetime)Parameters#
| Name | Type | Description |
|---|---|---|
| datetime | datetime |
The input datetime value. |
Returns#
An int from 1 to 366 representing the day number within the year.
Use case examples#
Track daily request counts across the year to spot high-traffic and low-traffic periods.
Query
['sample-http-logs']
| extend day_of_year = dayofyear(_time)
| summarize request_count = count() by day_of_year
| sort by day_of_year ascOutput
| day_of_year | request_count |
|---|---|
| 1 | 482 |
| 2 | 531 |
| 3 | 497 |
This query counts the total number of HTTP requests for each day of the year, helping you identify seasonal traffic patterns.
Monitor trace volume trends by day of the year for each service to detect seasonal performance shifts.
Query
['otel-demo-traces']
| extend day_of_year = dayofyear(_time)
| summarize trace_count = count() by day_of_year, ['service.name']
| sort by day_of_year ascOutput
| day_of_year | service.name | trace_count |
|---|---|---|
| 1 | frontend | 312 |
| 2 | frontend | 287 |
| 3 | frontend | 345 |
This query tracks how trace volume changes day by day throughout the year for each service, revealing seasonal trends.
Find the busiest days of the year for server errors to identify recurring problem periods.
Query
['sample-http-logs']
| where toint(status) >= 500
| extend day_of_year = dayofyear(_time)
| summarize error_count = count() by day_of_year
| sort by error_count descOutput
| day_of_year | error_count |
|---|---|
| 142 | 87 |
| 98 | 64 |
| 215 | 53 |
This query ranks days of the year by server error count, helping you pinpoint recurring high-error periods.
List of related functions#
- dayofmonth: Returns the day number within the month from a datetime.
- dayofweek: Returns the day of the week as an integer, useful for weekday versus weekend analysis.
- datetime_part: Extracts a specific date part (such as day or year) as an integer.
- monthofyear: Returns the month number from a datetime, useful for monthly grouping.
- getyear: Returns the year from a datetime, useful for year-level aggregation.
Other query languages#
Splunk SPL users
In Splunk SPL, you typically use the strftime function with the %j specifier to extract the day of the year. In APL, the dayofyear function directly returns the day number within the year from a datetime value.
Splunk example
... | eval doy=strftime(_time, "%j")APL equivalent
... | extend day_of_year = dayofyear(_time)ANSI SQL users
In ANSI SQL, you often use EXTRACT(DOY FROM timestamp) or DAYOFYEAR(timestamp). The APL dayofyear function provides the same result, returning an integer from 1 to 366.
SQL example
SELECT EXTRACT(DOY FROM timestamp_column) AS day_of_year FROM events;APL equivalent
['dataset']
| extend day_of_year = dayofyear(_time)