Dashboards & Visualizations

Splunk Timechart span

Splunk3
Explorer

Hi I am trying to count the number of jobs till now and want to show the daily trend using timechart command. Not able to get , may be I am messing up with span option

for eg.. total jobs executed till now is 100 and there is trend of 10 jobs increased today 

tomorrow it should show 110 and trend of tomorrows increase job 

command - index=.......... projects="*" job_id="*" | dedup job_id | timechart span=60d count

In picture you can see that total events are shown 1688 , I need that as single value and daily trend over itsplunk query.PNG

 

 

 

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
index=_internal 
| bin _time span=1d 
| sort 0 _time
| stats count by _time
| streamstats sum(count) as total
| table _time total

View solution in original post

Splunk3
Explorer

Yes, but here I need total no of jobs executed till now i.e 1688 in this case( see the total no of events ) and on that I want daily trend 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
index=_internal 
| bin _time span=1d 
| sort 0 _time
| stats count by _time
| streamstats sum(count) as total
| table _time total

Splunk3
Explorer

Thank you it worked -:) 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Shouldn't span=1d if you want daily trends?

0 Karma
Get Updates on the Splunk Community!

This Week's Community Digest - Splunk Community Happenings [9.26.22]

Get the latest news and updates from the Splunk Community here! Upcoming User Group Events! 👏 Check ...

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...