Overview

endofday

You can use endofday to create daily time boundaries for aggregation, reporting, and filtering. This is especially useful when you need to bucket events into daily intervals or determine how much time remains until the end of a given day.

Use it when you want to:

  • Define end-of-day boundaries for daily reports and dashboards.
  • Aggregate events up to the end of each day.
  • Calculate the remaining time in a day for each event.

Usage#

Syntax#

endofday(datetime [, offset])

Parameters#

Name Type Description
datetime datetime The input datetime value.
offset long Optional: The number of days to offset from the input date. Use negative values for past dates and positive values for future dates. Default is 0.

Returns#

A datetime representing the end of the day (23:59:59.9999999) for the given date, shifted by the offset if specified.

Use case examples#

Calculate how far each request is from the end of the day to understand the distribution of traffic within daily windows.

Query

['sample-http-logs']
| extend end = endofday(_time)
| extend remaining_ms = datetime_diff('millisecond', end, _time)
| project _time, end, remaining_ms, method

Run in Playground

Output

_time end remaining_ms method
2024-11-14T10:22:31Z 2024-11-14T23:59:59.9999999Z 49048000 GET
2024-11-14T18:45:12Z 2024-11-14T23:59:59.9999999Z 18888000 POST
2024-11-14T23:01:44Z 2024-11-14T23:59:59.9999999Z 3496000 GET

This query computes the time remaining until the end of the day for each request, useful for understanding traffic distribution across daily windows.

Aggregate trace counts to end-of-day boundaries for each service to create daily summaries.

Query

['otel-demo-traces']
| extend day_end = endofday(_time)
| summarize trace_count = count() by day_end, ['service.name']
| sort by day_end asc

Run in Playground

Output

day_end service.name trace_count
2024-11-14T23:59:59.9999999Z frontend 1523
2024-11-15T23:59:59.9999999Z frontend 1487
2024-11-16T23:59:59.9999999Z frontend 1601

This query groups traces by end-of-day boundaries for each service, giving you a daily count of trace activity.

Count error requests grouped by end-of-day boundaries to track daily error volumes.

Query

['sample-http-logs']
| where toint(status) >= 400
| extend day_end = endofday(_time)
| summarize error_count = count() by day_end
| sort by day_end asc

Run in Playground

Output

day_end error_count
2024-11-14T23:59:59.9999999Z 67
2024-11-15T23:59:59.9999999Z 43
2024-11-16T23:59:59.9999999Z 89

This query counts HTTP errors by end-of-day boundaries, helping you monitor daily error trends and detect spikes.

  • startofday: Returns the start of the day for a datetime, useful for defining the beginning of daily intervals.
  • endofweek: Returns the end of the week for a datetime.
  • endofmonth: Returns the end of the month for a datetime.
  • endofyear: Returns the end of the year for a datetime.
  • now: Returns the current datetime, useful for calculating time until end of day.

Other query languages#

Splunk SPL users

In Splunk SPL, there is no direct equivalent to endofday. You typically use relative_time with snap-to syntax such as @d+1d-1s to approximate the end of the day. In APL, the endofday function handles this directly.

Splunk example

... | eval end=relative_time(_time, "@d+1d-1s")

APL equivalent

... | extend end = endofday(_time)
ANSI SQL users

In ANSI SQL, you typically combine DATE_TRUNC with interval arithmetic to get the end of the day. In APL, the endofday function provides this directly and supports an optional day offset.

SQL example

SELECT DATE_TRUNC('day', timestamp_column) + INTERVAL '1 day' - INTERVAL '1 second' AS end_of_day FROM events;

APL equivalent

['dataset']
| extend end_of_day = endofday(_time)

Updated

Was this page helpful?