<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Metrics Index - How to get metric_searchtime field value in search result in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Metrics-Index-How-to-get-metric-searchtime-field-value-in-search/m-p/393541#M70274</link>
    <description>&lt;P&gt;For mstats to project by time you need to give it a span, so queries of the form:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| mstats avg("abc") WHERE index="xyz" span=10s
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It's not possible to aggregate time, so you can't do things like latest("_time").&lt;/P&gt;</description>
    <pubDate>Tue, 09 Apr 2019 15:58:13 GMT</pubDate>
    <dc:creator>thaggie_splunk</dc:creator>
    <dc:date>2019-04-09T15:58:13Z</dc:date>
    <item>
      <title>Metrics Index - How to get metric_searchtime field value in search result</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Metrics-Index-How-to-get-metric-searchtime-field-value-in-search/m-p/393540#M70273</link>
      <description>&lt;P&gt;I uploaded a csv file in metric index. I can see index's data there is no issue in that.&lt;/P&gt;

&lt;P&gt;My query is:&lt;BR /&gt;
I want to get metric_timestamp in search query to perform some action on that. Is it possible to use "metric_timestamp" field in mstat commands? I always get error whenever I tried to apply any statistical function (i.e. latest etc) on "metric_timestamp" or used it as a dimension field (where index=xyz by metric_timestamp). &lt;/P&gt;

&lt;P&gt;mcatalog just displays the schema, not the values from "metric_timestamp" field. &lt;/P&gt;

&lt;P&gt;Any help is greatly appreciated. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:59:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Metrics-Index-How-to-get-metric-searchtime-field-value-in-search/m-p/393540#M70273</guid>
      <dc:creator>shadabgaur</dc:creator>
      <dc:date>2020-09-29T23:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: Metrics Index - How to get metric_searchtime field value in search result</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Metrics-Index-How-to-get-metric-searchtime-field-value-in-search/m-p/393541#M70274</link>
      <description>&lt;P&gt;For mstats to project by time you need to give it a span, so queries of the form:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| mstats avg("abc") WHERE index="xyz" span=10s
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It's not possible to aggregate time, so you can't do things like latest("_time").&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 15:58:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Metrics-Index-How-to-get-metric-searchtime-field-value-in-search/m-p/393541#M70274</guid>
      <dc:creator>thaggie_splunk</dc:creator>
      <dc:date>2019-04-09T15:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: Metrics Index - How to get metric_searchtime field value in search result</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Metrics-Index-How-to-get-metric-searchtime-field-value-in-search/m-p/393542#M70275</link>
      <description>&lt;P&gt;Thanks for quick response Thaggie. So, we cannot use this field "metric_timestamp" in anywhere in our search except spanning the chart based on it. &lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 00:54:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Metrics-Index-How-to-get-metric-searchtime-field-value-in-search/m-p/393542#M70275</guid>
      <dc:creator>shadabgaur</dc:creator>
      <dc:date>2019-04-10T00:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Metrics Index - How to get metric_searchtime field value in search result</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Metrics-Index-How-to-get-metric-searchtime-field-value-in-search/m-p/393543#M70276</link>
      <description>&lt;P&gt;That's right&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 14:39:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Metrics-Index-How-to-get-metric-searchtime-field-value-in-search/m-p/393543#M70276</guid>
      <dc:creator>thaggie_splunk</dc:creator>
      <dc:date>2019-04-10T14:39:03Z</dc:date>
    </item>
  </channel>
</rss>

