Dashboards & Visualizations

timerange rounding -1h@5m

0range
Communicator

How to round search time to 5 mins?
If i use span=5m fro timechart the time rounded to 1 minute looks awful.

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

I'd also like more details about your question. In the meantime, here's another guess: Are you annoyed by "half buckets" when your time range starts at 12:03 and it sticks those two minutes until 12:05 into a bucket, messing up counts and sums? Try adding partial=f to your timechart, it'll discard those buckets.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

I'd also like more details about your question. In the meantime, here's another guess: Are you annoyed by "half buckets" when your time range starts at 12:03 and it sticks those two minutes until 12:05 into a bucket, messing up counts and sums? Try adding partial=f to your timechart, it'll discard those buckets.

0range
Communicator

Thanks) partial is enough.

0 Karma

strive
Influencer

index=_internal earliest=-1h@h latest=-0h@h | timechart span=5m count by source

This sets span as 5m and you get 12 intervals.

If you give more details, it will be helpful to answer your question

0 Karma

strive
Influencer

You mean you need time in interval of 5 minutes

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...