Deployment Architecture

timechart span not working

zachsisinst
Explorer
index="myindex" cluster="mycluster" http_request="/"
| bucket _time span=5m
| timechart count by x_forwarded_for useother=false span=5m

the time buckets i'm seeing on this |timechart are half hour buckets instead of 5m buckets. What am I doing wrong?

0 Karma

efavreau
Motivator

@zachsisinst I don't think you need line two, because the timechart command takes care of that for you.

###

If this reply helps you, an upvote would be appreciated.
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi zachsisinst,

timechart seams to be very picky about the location of the span option, try this:

 | timechart span=5m count by x_forwarded_for useother=false 

Hope this helps ...

cheers, MuS

UPDATE:

it is right here https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/timechart

timechart [sep=<string>] [format=<string>] [partial=<bool>] [cont=<bool>] [limit=<int>]
[agg=<stats-agg-term>] [<bin-options>... ]
( (<single-agg> [BY <split-by-clause>] ) | (<eval-expression>) BY <split-by-clause> )
[<dedup_splitvals>]

That said the span= or bin option needs to be on the left side of the by split clause 🙂

cheers, MuS

MuS
SplunkTrust
SplunkTrust

See the updated post

cheers, MuS

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...