Dashboards & Visualizations

timechart not working

sarit_s
Communicator

Hello
I have this query :

index="report" Computer_Name="*"  |chart dc(Category__Names_of_Patches) as totalNumberOfPatches by Computer_Name
| eval exposure_level = case(
    totalNumberOfPatches >= 3 AND totalNumberOfPatches <= 6, "Low Exposure",
    totalNumberOfPatches >= 7 AND totalNumberOfPatches <= 10, "Medium Exposure", 
    totalNumberOfPatches >= 11, "High Exposure", 
    totalNumberOfPatches == 2, "Compliant",
    totalNumberOfPatches == 1, "<not reported>",
    1=1,"other"
  )

| stats count(Computer_Name) as totalNumberOfPatches by exposure_level

| eval category=exposure_level

Looks like I've lost the _time field on the way so when im trying to run timechart im getting no results

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Correct, after the stats command you will only have totalNumberOfPatches and exposure_level. If you need _time after this point it should be added to the by clause, however, you may wish to bin it first, or replace the stats command with timechart

0 Karma

sarit_s
Communicator

Well, ive changed it to this :

| eval category=exposure_level
| timechart span=1d count(Computer_Name) as totalNumberOfPatches by category

but still no results

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Sorry, I missed the chart command on your first line. This is the command which is removing the timestamps.

0 Karma

sarit_s
Communicator

so what sould i do ? replacing it with timechart returns also no results

0 Karma

sarit_s
Communicator

solved it by changing to stats. thanks

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...