<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to correct timechart after upgrading in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-correct-timechart-after-upgrading/m-p/593871#M206708</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244898"&gt;@Jaylon&lt;/a&gt;&amp;nbsp; - Try something like the below as suggested by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;timechart [| makeresults | eval range="$timeRange$" | eval search=case(range=="-6h", "span=30m ", range=="-1d", "span=1h ", range=="-3d", "span=2h ", range=="-7d", "span=4h ")]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 15 Apr 2022 08:18:59 GMT</pubDate>
    <dc:creator>VatsalJagani</dc:creator>
    <dc:date>2022-04-15T08:18:59Z</dc:date>
    <item>
      <title>How to correct timechart after upgrading</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-correct-timechart-after-upgrading/m-p/593853#M206703</link>
      <description>&lt;P&gt;timechart [stats count | eval range="$timeRange$" | eval search=case(range=="-6h", "span=30m ", range=="-1d", "span=1h ", range=="-3d", "span=2h ", range=="-7d", "span=4h ")] can't work after upgrade splunk from 8.0.6 to 8.2.5.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2022 03:00:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-correct-timechart-after-upgrading/m-p/593853#M206703</guid>
      <dc:creator>Jaylon</dc:creator>
      <dc:date>2022-04-15T03:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to correct timechart after upgrading</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-correct-timechart-after-upgrading/m-p/593858#M206705</link>
      <description>&lt;P&gt;Regardless of update I don't see this search working properly unles you were very very lucky so far.&lt;/P&gt;&lt;P&gt;The subsearch starts with "stats count". Since you don't specify any command, it's treated as arguments for the implicit search command. So you're searching for the events containing&amp;nbsp; both words "stats" and "count" in your user's default index using time picker's timerange. It's probably not what you wanted.&lt;/P&gt;&lt;P&gt;You might want to start your search with "| makeresults" instead of this search.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2022 05:01:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-correct-timechart-after-upgrading/m-p/593858#M206705</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-04-15T05:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to correct timechart after upgrading</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-correct-timechart-after-upgrading/m-p/593871#M206708</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244898"&gt;@Jaylon&lt;/a&gt;&amp;nbsp; - Try something like the below as suggested by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;timechart [| makeresults | eval range="$timeRange$" | eval search=case(range=="-6h", "span=30m ", range=="-1d", "span=1h ", range=="-3d", "span=2h ", range=="-7d", "span=4h ")]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2022 08:18:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-correct-timechart-after-upgrading/m-p/593871#M206708</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-04-15T08:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to correct timechart after upgrading</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-correct-timechart-after-upgrading/m-p/593883#M206713</link>
      <description>&lt;P&gt;It looks like you are trying to set the span based on the value of a token. Why not create a additional token at the same time as the timeRange token based on the options you want?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;eval token="span"&amp;gt;case($timeRange$=="-6h", "span=30m ", $timeRange$=="-1d", "span=1h ", $timeRange$=="-3d", "span=2h ", $timeRange$=="-7d", "span=4h ")&amp;lt;/eval&amp;gt;

timechart $span$&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 15 Apr 2022 09:55:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-correct-timechart-after-upgrading/m-p/593883#M206713</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-04-15T09:55:55Z</dc:date>
    </item>
  </channel>
</rss>

