Deployment Architecture

Help bucketing time with mcollect?

daniel333
Builder

all,

I am running this search to collect exceptions by host. I am bucketing into 1min intervals. However when I go back with mstats or the metrics work bench - data is being time stamped at the point of the summary job run rather than at the _time of the bucket itself.

tag=java host=mydc* priority=error OR priority=warning OR priority=fatal java_exception=* role=* host=*abc*
| rex field=host (?<pod>\w\w\w\w\d\d)
| bin _time span=1m 
| stats first(_time) as _time count by pod,role,java_exception, priority
| rename count as _value 
| eval metric_name="dpw3.toyrus.java.exceptions.count"
| mcollect index=testmetrics 

The results table LOOKS fine. But the final product has the wrong time.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...