timechart seams to be very picky about the location of the
span option, try this:
| timechart span=5m count by x_forwarded_for useother=false
Hope this helps ...
timechart [sep=<string>] [format=<string>] [partial=<bool>] [cont=<bool>] [limit=<int>] [agg=<stats-agg-term>] [<bin-options>... ] ( (<single-agg> [BY <split-by-clause>] ) | (<eval-expression>) BY <split-by-clause> ) [<dedup_splitvals>]
That said the
span= or bin option needs to be on the left side of the
by split clause 🙂