<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: bin and bucket command examples to practice in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336571#M12586</link>
    <description>&lt;P&gt;i raised a request but i have not get the approval for Slack chat. &lt;/P&gt;</description>
    <pubDate>Mon, 16 Apr 2018 09:20:03 GMT</pubDate>
    <dc:creator>logloganathan</dc:creator>
    <dc:date>2018-04-16T09:20:03Z</dc:date>
    <item>
      <title>bin and bucket command examples to practice</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336568#M12583</link>
      <description>&lt;P&gt;Could anyone please give bin and bucket command examples to practice&lt;/P&gt;</description>
      <pubDate>Sun, 15 Apr 2018 17:16:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336568#M12583</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-04-15T17:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: bin and bucket command examples to practice</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336569#M12584</link>
      <description>&lt;P&gt;Most of the time I use &lt;CODE&gt;bin&lt;/CODE&gt; is to bucket time into segments. &lt;/P&gt;

&lt;P&gt;Any other time I use &lt;CODE&gt;bin&lt;/CODE&gt; is to see how distributed data is. So it will follow the format below&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| bin &amp;lt;FIELD&amp;gt; span=&amp;lt;SEGMENT_Size&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;OR &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| bin _time span=1h
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 15 Apr 2018 17:30:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336569#M12584</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-04-15T17:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: bin and bucket command examples to practice</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336570#M12585</link>
      <description>&lt;P&gt;@logloganathan, I would request you to at least try to research a bit before posting a question.&lt;/P&gt;

&lt;P&gt;Usual google search for you should be &lt;CODE&gt;Splunk &amp;lt;command you want to search&amp;gt;&lt;/CODE&gt; or even better &lt;CODE&gt;Splunk Docs &amp;lt;command you want to search&amp;gt;&lt;/CODE&gt;. Before posting to Splunk Answers you can search &lt;CODE&gt;Splunk Answer &amp;lt;command you want to search&amp;gt;&lt;/CODE&gt; (While you type in your question Splunk Answers will also suggest you previous answers on similar lines for you to refer).&lt;/P&gt;

&lt;P&gt;Following is the link to &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Bin"&gt;bin command Splunk Documentation&lt;/A&gt; which mentions that bucket is just and alias for bin command. It also has some examples.&lt;/P&gt;

&lt;P&gt;In case searching through &lt;A href="http://docs.splunk.com/Documentation"&gt;Splunk Docs&lt;/A&gt;, &lt;A href="http://dev.splunk.com/"&gt;Splunk Dev&lt;/A&gt;, &lt;A href="https://www.splunk.com/blog/homepage.html"&gt;Splunk Blogs&lt;/A&gt;, &lt;A href="https://answers.splunk.com/index.html"&gt;Splunk Answers&lt;/A&gt;, &lt;A href="https://www.splunk.com/en_us/training.html"&gt;Splunk Education&lt;/A&gt; or other online resources does not cater to your queries/issues you can mention the specifics so that community members can assist you with the same. Also as suggested earlier, Slack Chat on Splunk Channels in Splunk User Groups seems more appropriate channel for faster resolutions to specific problems you are facing.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Apr 2018 21:50:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336570#M12585</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-04-15T21:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: bin and bucket command examples to practice</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336571#M12586</link>
      <description>&lt;P&gt;i raised a request but i have not get the approval for Slack chat. &lt;/P&gt;</description>
      <pubDate>Mon, 16 Apr 2018 09:20:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336571#M12586</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-04-16T09:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: bin and bucket command examples to practice</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336572#M12587</link>
      <description>&lt;P&gt;@logloganathan, I see that you have down voted my comment. Down voting should only be reserved for suggestions/solutions that could be potentially harmful for a Splunk environment or goes completely against known best practices.&lt;/P&gt;

&lt;P&gt;Simply commenting with more information about what didn't work and what you've tried (or whatever other info may be relevant) would suffice to help you troubleshoot further.&lt;/P&gt;

&lt;P&gt;Refer to community guidelines (ironically again on Splunk Docs :)): &lt;A href="https://docs.splunk.com/Documentation/Splunkbase/splunkbase/Answers/Splunkcommunityguidelines"&gt;https://docs.splunk.com/Documentation/Splunkbase/splunkbase/Answers/Splunkcommunityguidelines&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I am curious to know as to how request to research on own before asking question is harmful for you/your environment. Please clarify!!!&lt;/P&gt;</description>
      <pubDate>Mon, 16 Apr 2018 14:25:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336572#M12587</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-04-16T14:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: bin and bucket command examples to practice</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336573#M12588</link>
      <description>&lt;P&gt;If you need to timechart &lt;CODE&gt;by&lt;/CODE&gt; multiple fields, then you can do &lt;CODE&gt;bin _time span=YourSpan | stats count BY field1 field2 ... fieldn _time&lt;/CODE&gt; as your base search and then in post-process searches, you can do &lt;CODE&gt;timechart span=YourSpan sum(count) BY field1&lt;/CODE&gt; and use &lt;CODE&gt;field2&lt;/CODE&gt; in the next panel, etc.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 23:00:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336573#M12588</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-04-20T23:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: bin and bucket command examples to practice</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336574#M12589</link>
      <description>&lt;P&gt;Thanks for your answer!!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 13:23:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336574#M12589</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-04-23T13:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: bin and bucket command examples to practice</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336575#M12590</link>
      <description>&lt;P&gt;Hello, &lt;BR /&gt;
After testing your solution I want to give more information :&lt;BR /&gt;
    bginQuery | bin _time span=$your_span$  | stats count as nb by field1, field2, ... fieldn, _time | search fieldx=yourValue | TIMECHART span=$your_span$ sum(nb) BY fieldy&lt;BR /&gt;
For the last timechart you need &lt;CODE&gt;sum&lt;/CODE&gt; the result and not just &lt;CODE&gt;count&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:04:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336575#M12590</guid>
      <dc:creator>mclane1</dc:creator>
      <dc:date>2020-09-29T22:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: bin and bucket command examples to practice</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336576#M12591</link>
      <description>&lt;P&gt;I updated my answer to be more specific.  You are completely correct and my original vague phrasing should have been more clear (I was trying to provide a more general answer).&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 23:47:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336576#M12591</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-11-20T23:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: bin and bucket command examples to practice</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336577#M12592</link>
      <description>&lt;P&gt;wow really helpful query&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 14:02:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/bin-and-bucket-command-examples-to-practice/m-p/336577#M12592</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-11-27T14:02:45Z</dc:date>
    </item>
  </channel>
</rss>

