Dashboards & Visualizations

timechart not working

sarit_s
Communicator

Hello
I have this query :

index="report" Computer_Name="*"  |chart dc(Category__Names_of_Patches) as totalNumberOfPatches by Computer_Name
| eval exposure_level = case(
    totalNumberOfPatches >= 3 AND totalNumberOfPatches <= 6, "Low Exposure",
    totalNumberOfPatches >= 7 AND totalNumberOfPatches <= 10, "Medium Exposure", 
    totalNumberOfPatches >= 11, "High Exposure", 
    totalNumberOfPatches == 2, "Compliant",
    totalNumberOfPatches == 1, "<not reported>",
    1=1,"other"
  )

| stats count(Computer_Name) as totalNumberOfPatches by exposure_level

| eval category=exposure_level

Looks like I've lost the _time field on the way so when im trying to run timechart im getting no results

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Correct, after the stats command you will only have totalNumberOfPatches and exposure_level. If you need _time after this point it should be added to the by clause, however, you may wish to bin it first, or replace the stats command with timechart

0 Karma

sarit_s
Communicator

Well, ive changed it to this :

| eval category=exposure_level
| timechart span=1d count(Computer_Name) as totalNumberOfPatches by category

but still no results

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Sorry, I missed the chart command on your first line. This is the command which is removing the timestamps.

0 Karma

sarit_s
Communicator

so what sould i do ? replacing it with timechart returns also no results

0 Karma

sarit_s
Communicator

solved it by changing to stats. thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...