Splunk Enterprise

How to get sum of a value within a period of 15 min?

chandankr
Path Finder

I have an input of value is like an odometer so it's cumulative. I collect a sample every 15 minutes. If I want to create a timechart that shows the total value of 15 min duration. how would I do that? See example below.

1/17/2023 0:01:00 value 6
1/17/2023 0:02:00 value 6
1/17/2023 0:03:00 value 6
1/17/2023 0:09:00 value 7
1/17/2023 0:10:00 value 6
1/17/2023 0:11:00 value 7
1/17/2023 0:12:00 value 8
1/17/2023 0:15:00 value 8


from 1 minute to 15 minute total value is 54

1/17/2023 0:16:00 value 5
1/17/2023 0:17:00 value 8
1/17/2023 0:18:00 value 5
1/17/2023 0:29:00 value 7
1/17/2023 0:30:00 value 5

from 16 minute to 30 minute total value is 30

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

| timechart span=15m sum(value)

chandankr
Path Finder

@ITWhisperer this is not working 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Why/how?

What does it give you?

0 Karma

chandankr
Path Finder

 

@ITWhisperer  not getting result

chandankr_0-1674042654230.png

 

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You need to use only one timechart command

| timechart span=15m sum(active_state) as active_state sum(idle_state) as idle_state
0 Karma

chandankr
Path Finder

@ITWhisperer  still no result

chandankr_0-1674109931455.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Looks like your extract is not working. Can you share some raw events in a code block?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...