Dashboards & Visualizations

How can I group time in buckets for stacked bar chart?

rkassabov
Path Finder

I have a simple query that produces a stacked bar chart as follows:

index=xxx
| table time, info_owner_deptBusiness, avg_data_residualRisk_max
| chart count(avg_data_residualRisk_max) over time by info_owner_deptBusiness

I would like to group my events by "time" in buckets of 5 minute intervals. My time stamps look like this:

2017-12-20T00:40:08.701+0000

How can I accomplish this while preserving the stacked bar chart visualization?

Tags (2)
0 Karma
1 Solution

mayurr98
Super Champion

Try this:

index=xxx 
| bin span=5m _time 
| chart count(avg_data_residualRisk_max) over _time by info_owner_deptBusiness

View solution in original post

mayurr98
Super Champion

Try this:

index=xxx 
| bin span=5m _time 
| chart count(avg_data_residualRisk_max) over _time by info_owner_deptBusiness

rkassabov
Path Finder

Perfect, thank you!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...