<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help needed Timechart Query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-needed-Timechart-Query/m-p/628539#M218330</link>
    <description>&lt;P&gt;Dear experts ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am searching on my bot index, which contain conve-id and rest of the fields are stored as payload. Using spath i am able to extract required fields from payload into a table , now for trend analysis i want to use time chart command to see number of users per month , however its not working , below is the query for your reference , need help with the query :&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=idx_chatbot logpoint=response-in AND service="journeyService" OR service="watsonPostMessage"
|spath input=payload output=displayname path=context.displayName 
| spath input=payload output=Country path=context.countryCode 
| spath input=payload output=Intent path=intents{}.intent 
|spath input=payload output=ticketResponse 
       path=response.createTicketResponse.Message 
| table conversation-id timestamp service duration logpoint userFeedback displayname text Country Intent category ticketResponse payload
| dedup conversation-id
| timechart span=1mon count(displayName) &lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 26 Jan 2023 20:10:25 GMT</pubDate>
    <dc:creator>Macky_29</dc:creator>
    <dc:date>2023-01-26T20:10:25Z</dc:date>
    <item>
      <title>Help needed Timechart Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-needed-Timechart-Query/m-p/628539#M218330</link>
      <description>&lt;P&gt;Dear experts ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am searching on my bot index, which contain conve-id and rest of the fields are stored as payload. Using spath i am able to extract required fields from payload into a table , now for trend analysis i want to use time chart command to see number of users per month , however its not working , below is the query for your reference , need help with the query :&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=idx_chatbot logpoint=response-in AND service="journeyService" OR service="watsonPostMessage"
|spath input=payload output=displayname path=context.displayName 
| spath input=payload output=Country path=context.countryCode 
| spath input=payload output=Intent path=intents{}.intent 
|spath input=payload output=ticketResponse 
       path=response.createTicketResponse.Message 
| table conversation-id timestamp service duration logpoint userFeedback displayname text Country Intent category ticketResponse payload
| dedup conversation-id
| timechart span=1mon count(displayName) &lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 26 Jan 2023 20:10:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-needed-Timechart-Query/m-p/628539#M218330</guid>
      <dc:creator>Macky_29</dc:creator>
      <dc:date>2023-01-26T20:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: Help needed Timechart Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-needed-Timechart-Query/m-p/628541#M218332</link>
      <description>&lt;P&gt;"Its not working" gives us nothing to work with.&amp;nbsp; Help us help you by explaining what the expected results are and what you are getting from the current query.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 20:12:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-needed-Timechart-Query/m-p/628541#M218332</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-26T20:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: Help needed Timechart Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-needed-Timechart-Query/m-p/628569#M218345</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It doesn't give any result , below is the screenshot&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Macky_29_0-1674795974883.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23591i03CDBD67D81721C9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Macky_29_0-1674795974883.png" alt="Macky_29_0-1674795974883.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am expecting it gives me monthly count (trend)of distinct display name i.e. users in my case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 05:07:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-needed-Timechart-Query/m-p/628569#M218345</guid>
      <dc:creator>Macky_29</dc:creator>
      <dc:date>2023-01-27T05:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Help needed Timechart Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-needed-Timechart-Query/m-p/628570#M218346</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Macky_29_0-1674795926214.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23590i02656FB7C0148EC0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Macky_29_0-1674795926214.png" alt="Macky_29_0-1674795926214.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 05:09:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-needed-Timechart-Query/m-p/628570#M218346</guid>
      <dc:creator>Macky_29</dc:creator>
      <dc:date>2023-01-27T05:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Help needed Timechart Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-needed-Timechart-Query/m-p/628573#M218348</link>
      <description>&lt;P&gt;You can't do a timechart without the _time field and your table command effectively removes the _time field&lt;/P&gt;&lt;P&gt;Also, not sure why your timechart is count(displayName) as that is counting occurrences of that field in all the deduped conversation-id events - so unless it is blank in some events, it will be a 1:1 relationship with conversation-id.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would seem that you are looking to count the number of individual conversations, so you would get this by replacing your last 3 lines with&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| timechart span=1mon dc(conversation-id)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but if you are looking for distinct displayName then you can still replace the last 3 lines with&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| timechart span=1mon dc(displayName)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;unless you have have many &lt;STRONG&gt;_different_&amp;nbsp;&lt;/STRONG&gt;displayName values for a single conversation-id&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 05:25:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-needed-Timechart-Query/m-p/628573#M218348</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-01-27T05:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: Help needed Timechart Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-needed-Timechart-Query/m-p/628576#M218349</link>
      <description>&lt;P&gt;Thanks Bowesmana it works&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 05:50:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-needed-Timechart-Query/m-p/628576#M218349</guid>
      <dc:creator>Macky_29</dc:creator>
      <dc:date>2023-01-27T05:50:04Z</dc:date>
    </item>
  </channel>
</rss>

