<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hardcoded Time Bucketing in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Hardcoded-Time-Bucketing/m-p/413479#M41046</link>
    <description>&lt;P&gt;Hi guys, &lt;/P&gt;

&lt;P&gt;I was recently given a new data index that has hardcoded time stamps in the event rather than being based on _time. The events are also re-indexed every night rather than being ingested when the event occurred making this more complex.  For example, an event that happened aug 14th will have a hardcoded epoch of aug 14th yet the splunk _time date is yesterday evening. Using this data, I have been able to create a time chart but I am having trouble with months with no events. The months that have no events are being skipped (see below picture) because there is no data for that particular month. How can you create buckets based on the hard coded dates or create something to fill these no existent months?&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5589i1EA2DE775E6A5F13/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Aug 2018 18:29:24 GMT</pubDate>
    <dc:creator>zgoda</dc:creator>
    <dc:date>2018-08-20T18:29:24Z</dc:date>
    <item>
      <title>Hardcoded Time Bucketing</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Hardcoded-Time-Bucketing/m-p/413479#M41046</link>
      <description>&lt;P&gt;Hi guys, &lt;/P&gt;

&lt;P&gt;I was recently given a new data index that has hardcoded time stamps in the event rather than being based on _time. The events are also re-indexed every night rather than being ingested when the event occurred making this more complex.  For example, an event that happened aug 14th will have a hardcoded epoch of aug 14th yet the splunk _time date is yesterday evening. Using this data, I have been able to create a time chart but I am having trouble with months with no events. The months that have no events are being skipped (see below picture) because there is no data for that particular month. How can you create buckets based on the hard coded dates or create something to fill these no existent months?&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5589i1EA2DE775E6A5F13/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2018 18:29:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Hardcoded-Time-Bucketing/m-p/413479#M41046</guid>
      <dc:creator>zgoda</dc:creator>
      <dc:date>2018-08-20T18:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Hardcoded Time Bucketing</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Hardcoded-Time-Bucketing/m-p/413480#M41047</link>
      <description>&lt;P&gt;1) in your search you can assign the hardcoded epoch time value to&lt;CODE&gt;_time&lt;/CODE&gt; to put the event in the right place. &lt;/P&gt;

&lt;P&gt;2) use &lt;CODE&gt;continuous=t&lt;/CODE&gt; on your timechart to set the time gaps at 0. &lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 20:19:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Hardcoded-Time-Bucketing/m-p/413480#M41047</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2018-08-21T20:19:59Z</dc:date>
    </item>
  </channel>
</rss>

