Overview

dayofyear

You can use dayofyear to perform year-over-year comparisons by day, analyze seasonal trends, and track how metrics evolve throughout the year. This is especially useful for time-series analysis where you want to align data across multiple years by day number.

Use it when you want to:

  • Compare activity or metrics on the same day across different years.
  • Identify seasonal trends and patterns in log, trace, or security data.
  • Track progress through the year for cumulative reporting.

Usage#

Syntax#

dayofyear(datetime)

Parameters#

Name Type Description
datetime datetime The input datetime value.

Returns#

An int from 1 to 366 representing the day number within the year.

Use case examples#

Track daily request counts across the year to spot high-traffic and low-traffic periods.

Query

['sample-http-logs']
| extend day_of_year = dayofyear(_time)
| summarize request_count = count() by day_of_year
| sort by day_of_year asc

Run in Playground

Output

day_of_year request_count
1 482
2 531
3 497

This query counts the total number of HTTP requests for each day of the year, helping you identify seasonal traffic patterns.

Monitor trace volume trends by day of the year for each service to detect seasonal performance shifts.

Query

['otel-demo-traces']
| extend day_of_year = dayofyear(_time)
| summarize trace_count = count() by day_of_year, ['service.name']
| sort by day_of_year asc

Run in Playground

Output

day_of_year service.name trace_count
1 frontend 312
2 frontend 287
3 frontend 345

This query tracks how trace volume changes day by day throughout the year for each service, revealing seasonal trends.

Find the busiest days of the year for server errors to identify recurring problem periods.

Query

['sample-http-logs']
| where toint(status) >= 500
| extend day_of_year = dayofyear(_time)
| summarize error_count = count() by day_of_year
| sort by error_count desc

Run in Playground

Output

day_of_year error_count
142 87
98 64
215 53

This query ranks days of the year by server error count, helping you pinpoint recurring high-error periods.

  • dayofmonth: Returns the day number within the month from a datetime.
  • dayofweek: Returns the day of the week as an integer, useful for weekday versus weekend analysis.
  • datetime_part: Extracts a specific date part (such as day or year) as an integer.
  • monthofyear: Returns the month number from a datetime, useful for monthly grouping.
  • getyear: Returns the year from a datetime, useful for year-level aggregation.

Other query languages#

Splunk SPL users

In Splunk SPL, you typically use the strftime function with the %j specifier to extract the day of the year. In APL, the dayofyear function directly returns the day number within the year from a datetime value.

Splunk example

... | eval doy=strftime(_time, "%j")

APL equivalent

... | extend day_of_year = dayofyear(_time)
ANSI SQL users

In ANSI SQL, you often use EXTRACT(DOY FROM timestamp) or DAYOFYEAR(timestamp). The APL dayofyear function provides the same result, returning an integer from 1 to 366.

SQL example

SELECT EXTRACT(DOY FROM timestamp_column) AS day_of_year FROM events;

APL equivalent

['dataset']
| extend day_of_year = dayofyear(_time)

Updated

Was this page helpful?