<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TimeChart Syntax in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/TimeChart-Syntax/m-p/691322#M235413</link>
    <description>&lt;P&gt;This is a little confusing. &amp;nbsp;You are almost there:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=web sourcetype=access_combined status=200 productId=*
|timechart sum(price) as DailySales count as UnitsSold&lt;/LI-CODE&gt;&lt;P&gt;Is there something else we need to know?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jun 2024 18:13:17 GMT</pubDate>
    <dc:creator>yuanliu</dc:creator>
    <dc:date>2024-06-21T18:13:17Z</dc:date>
    <item>
      <title>TimeChart Syntax</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TimeChart-Syntax/m-p/691320#M235411</link>
      <description>&lt;P&gt;Stuck again and not sure what I'm missing... I have the first two steps, but cannot figure out the syntax to use Timechart to count all events as a specific label. Any help is greatly appreciated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Task:&amp;nbsp;&amp;nbsp;Use timechart to calculate the sum of price as "DailySales" and all count all events as "UnitsSold".&lt;/P&gt;
&lt;P&gt;What I have so far:&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=web sourcetype=access_combined status=200 productId=*
|timechart sum(price) as DailySales&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 21 Jun 2024 23:34:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TimeChart-Syntax/m-p/691320#M235411</guid>
      <dc:creator>Substance82</dc:creator>
      <dc:date>2024-06-21T23:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: TimeChart Syntax</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TimeChart-Syntax/m-p/691322#M235413</link>
      <description>&lt;P&gt;This is a little confusing. &amp;nbsp;You are almost there:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=web sourcetype=access_combined status=200 productId=*
|timechart sum(price) as DailySales count as UnitsSold&lt;/LI-CODE&gt;&lt;P&gt;Is there something else we need to know?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 18:13:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TimeChart-Syntax/m-p/691322#M235413</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-06-21T18:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: TimeChart Syntax</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TimeChart-Syntax/m-p/691323#M235414</link>
      <description>&lt;P&gt;Lol almost there, but a million miles away. I attempted something similar, but didn't fair well. Thanks a million.&amp;nbsp; Still working through a few new modules, but learning more each day.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 18:16:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TimeChart-Syntax/m-p/691323#M235414</guid>
      <dc:creator>Substance82</dc:creator>
      <dc:date>2024-06-21T18:16:22Z</dc:date>
    </item>
  </channel>
</rss>

