Splunk Enterprise

How to get sum of a value within a period of 15 min?

chandankr
Path Finder

I have an input of value is like an odometer so it's cumulative. I collect a sample every 15 minutes. If I want to create a timechart that shows the total value of 15 min duration. how would I do that? See example below.

1/17/2023 0:01:00 value 6
1/17/2023 0:02:00 value 6
1/17/2023 0:03:00 value 6
1/17/2023 0:09:00 value 7
1/17/2023 0:10:00 value 6
1/17/2023 0:11:00 value 7
1/17/2023 0:12:00 value 8
1/17/2023 0:15:00 value 8


from 1 minute to 15 minute total value is 54

1/17/2023 0:16:00 value 5
1/17/2023 0:17:00 value 8
1/17/2023 0:18:00 value 5
1/17/2023 0:29:00 value 7
1/17/2023 0:30:00 value 5

from 16 minute to 30 minute total value is 30

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

| timechart span=15m sum(value)

chandankr
Path Finder

@ITWhisperer this is not working 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Why/how?

What does it give you?

0 Karma

chandankr
Path Finder

 

@ITWhisperer  not getting result

chandankr_0-1674042654230.png

 

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You need to use only one timechart command

| timechart span=15m sum(active_state) as active_state sum(idle_state) as idle_state
0 Karma

chandankr
Path Finder

@ITWhisperer  still no result

chandankr_0-1674109931455.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Looks like your extract is not working. Can you share some raw events in a code block?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...