Given the following Splunk query, I'm able to create a nice line chart.
... | timechart span=7d count by my_field
I'd like to create a smoother line chart by instead charting the daily average count. How do I do that?
This is what I was looking for:
... | timechart span=1d count by my_field | bucket _time span=1w | stats avg(val1), avg(val2), avg(val3) by _time
a change span=7d to span=1d to get daily granularity.
You can also use streamstats to smooth it more if that is needed.
Changing the span to daily actually makes the line report less smooth. I'll check out streamstats. Thanks.