i have a search like so :
| dbxquery query="SELECT some select statement
| eval u_total_time=u_total_time/1000
| chart avg(u_total_time) over u_real_hit_time by u_short_description span=1m
However the span=1 seems to be ignored and the results are still presenting in second intervals.
I have moved the span cmd to after the chart cmd and also tried using stats and timechart but the span cmd is ignored in all searches.
Ideas ?
cheers.
The span attribute works on the column preceding it. Does the u_short_description field contains timestamp in epoch format? If the u_real_hit_time field contains timestamp, then you need to move span just after that in chart command.
| dbxquery query="SELECT some select statement
| eval u_total_time=u_total_time/1000
| chart avg(u_total_time) over u_real_hit_time span=1m by u_short_description
See this for example
http://docs.splunk.com/Documentation/Splunk/6.5.3/SearchReference/Chart#6:_Chart_the_number_of_event...