Splunk Search

Bucket Listing

deusaquilus
New Member

Ok, first off this has nothing to do with the colloquial notion of a 'bucket list'.
What I'm trying to do is to run a query that makes buckets via two text fields: Job and Counter. What I need is basically something like this:

index=main | chart list(value) as values by job,counter

Only instead of a list of all the values, I want to have a list of buckets e.g. something that might look like this:

index=main | chart list(bucket bins=5 value) as values by job,counter

The reason I want to do this is because I need to index these buckets in order to have them quickly available in a reporting chart. How do I do the above operation?

0 Karma

gkanapathy
Splunk Employee
Splunk Employee
index=main | bucket bins=5 value | chart list(value) as values by job,counter
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...