Dashboards & Visualizations

histogram creation query

surekhasplunk
Communicator

Hi,

I have a query which currently shows the port usage. Now i want to show the same for each month. i.e. for a span of 1 month.
Somehow my code is not working can you please help.

index=bla bla query
Tags (2)
0 Karma
1 Solution

Sukisen1981
Champion

something like this?

    | bin span=1mon _time |  stats count(type) by _time,Value,linkSpeed

View solution in original post

0 Karma

Sukisen1981
Champion

something like this?

    | bin span=1mon _time |  stats count(type) by _time,Value,linkSpeed
0 Karma

surekhasplunk
Communicator

Hi @Sukisen1981

Thanks for the reply my time field is called lastUpdated and the value looks like this : 2019-04-16T04:28:58+02:00

So when i try to put span=1mon it atually gives all records rather than spanning it for 1 month.
Do i need to edit the lastUpdated field to get only the date rather than the full date and time ?

Please help

0 Karma

Sukisen1981
Champion

hi @surekhasplunk
Yes , remember I am applying the bin command on _time , but you have a custom time field, so
| eval lastUpdated=strptime(lastUpdated,"%Y-%m-%d") |eval _time=lastUpdated|bin span=1mon _time |rest of the stuff....

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...