Deployment Architecture

Does bucket/bin command work from a lookup table/KVStore?

splunkrocks2014
Communicator

I have a timestamp column, my_time, stored in my kvstore, my_kv. I wanted to generate a report, but I got "No results found."

| inputlookup my_kv | bucket span=1h my_time | timechart count

I wonder if the bin/bucket command works for a lookup or kvstore. If not, are there other solutions? Thanks.

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

Yes, it does. All bin does is round down to the nearest specifier; there is no magic. The problem is that timechart in your case works only on _time so it is ignoring your my_time field. You need | rename my_time AS _time and then it will work.

View solution in original post

woodcock
Esteemed Legend

Yes, it does. All bin does is round down to the nearest specifier; there is no magic. The problem is that timechart in your case works only on _time so it is ignoring your my_time field. You need | rename my_time AS _time and then it will work.

splunkrocks2014
Communicator

Thank you very much!

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...