week_of_year
You can use week_of_year to group records by week when analyzing trends over time. This is especially useful for weekly aggregation in dashboards, anomaly detection, and cohort analysis.
Use it when you want to:
- Track activity or metrics week by week.
- Normalize data across different timeframes by weekly intervals.
- Generate week-based summaries across log, trace, or security datasets.
Usage#
Syntax#
week_of_year(datetime)Parameters#
| Name | Type | Description |
|---|---|---|
| datetime | datetime |
The input datetime value. |
Returns#
A long representing the ISO 8601 week number (from 1 to 53).
Use case examples#
Group HTTP log events by week to understand traffic trends and average request duration.
Query
['sample-http-logs']
| extend week = week_of_year(_time)
| summarize avg(req_duration_ms) by week
| sort by week ascOutput
| week | avg_req_duration_ms |
|---|---|
| 1 | 243.8 |
| 2 | 251.1 |
| 3 | 237.4 |
This query extracts the ISO week number for each record and calculates the average request duration per week.
Use weekly grouping to monitor changes in span durations for frontend services over time.
Query
['otel-demo-traces']
| where ['service.name'] == 'frontend'
| extend week = week_of_year(_time)
| summarize avg_duration = avg(duration) by week
| sort by week ascOutput
| week | avg_duration |
|---|---|
| 1 | 00:00:01.2340000 |
| 2 | 00:00:01.1750000 |
| 3 | 00:00:01.2890000 |
This query shows how the average span duration changes weekly for the frontend service.
Count HTTP errors by week to detect unusual spikes in failed requests.
Query
['sample-http-logs']
| where status startswith '5'
| extend week = week_of_year(_time)
| summarize error_count = count() by week
| sort by week ascOutput
| week | error_count |
|---|---|
| 1 | 18 |
| 2 | 34 |
| 3 | 12 |
This query detects week-by-week patterns in server error frequency, helping identify problem periods.
Other query languages#
Splunk SPL users
In Splunk SPL, you typically use the strftime function with the %V or %U specifiers to extract the week of the year. In APL, the week_of_year function directly extracts the ISO 8601 week number from a datetime.
Splunk example
... | eval week=strftime(_time, "%V")APL equivalent
... | extend week = week_of_year(_time)ANSI SQL users
In ANSI SQL, you often use EXTRACT(WEEK FROM timestamp) or DATEPART(WEEK, timestamp). These implementations may differ slightly across platforms in how they define the first week of the year. APL uses the ISO 8601 definition via week_of_year.
SQL example
SELECT EXTRACT(WEEK FROM timestamp_column) AS week FROM events;APL equivalent
['dataset']
| extend week = week_of_year(_time)