I'm looking for something like seq for times in Splunk.
|seq from=now to=1d span=4h
would generate events with _time as
Do you know of a way to achieve this behavior? bucket and bin work similar, but need a start and end event. That's why the next best thing I could build was
|stats count | fields - count |eval _time=now()-7*24*3600 |append [|stats count | fields - count |eval _time=now()+21*24*3600] | bucket _time span=4h |makecontinuous _time span=4h
which is not very nice to look at and only approximately what I wanted (start and end don't exactly match).
Gentimes. Another hour wasted which Splunk already spent for me 😄
View solution in original post