Reporting

TimeChart report with accrued event count

shorgan
New Member

How can I build a report to show the total count of a specific event over time. All of my timecharts are showing spikes over the time range but not accruing the number throughout.

Tags (1)
0 Karma

lguinn2
Legend

I am not sure what you mean by "accruing the number throughout". It would be helpful to see your actual search.

If you want a timechart that counts events, you can do this

yoursearchhere | timechart count

If you want to specify the time interval you can do this

yoursearchhere | timechart count span=1h

If you want to see the count as an ever-increasing number, I guess you could do this

yoursearchhere 
| timechart count as hourlyCount span=1h
| streamstats sum(hourlyCount) as count
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...