Deployment Architecture

bins command returns too few bins

drpog
New Member

Hi
I have a long list of measurements called standardised with values between 0.0 and 1.0 I was to display the distribution of the frequency these values in a histogram e.g.

Range Count
0.0 - 0.1 10
0.1 - 0.2 40

and so on. I run my command:

source="MessageTimes.csv" | bin standardised bins=10 | stats count by standardised

What I get back is 2 bins not 10 ( see the attached picture).

alt text

0 Karma

drpog
New Member

Thanks for the reply - but while it is nice to see a workaround that will work in this particular instance I am really asking why in general the

bins=10

option returns ONLY 2 bins!

I imagine that the span workaround will work in fact in this case I can prob. dispense with the bins=10 alltogether and just use :

| bin standardised span=0.1

I assume the whole point of bins=10 is that I don't have to go through my data and calculate a suitable range span, that Splunk will work out automatically a suitable span range for me.

0 Karma

HiroshiSatoh
Champion

try this!

| bin standardised bins=10 span=0.1

0 Karma

HiroshiSatoh
Champion

It is not good if there is "0.0". Please workaround.

ex.
span=0.1
OR
|eval standardised=standardised+0.01

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...