Splunk Search

Can you help me with a query that uses the latest function with a timechart command?

james_n
Path Finder

HI,

I have a query index=something | timechart latest(fieldA) as datavalues by dataNames.

when i select the time duration Today or Yesterday up to last 30days , it's working fine. If I select the last 3 months, it's displaying the wrong results.

Can you please help me on this?

0 Karma

bjoernjensen
Contributor

Hey,

How do you select "last 3 months"? Do you use any time snapping:
timechart_time_snipping

you can force the time using earliest and latest as filter:
index=something earliest=-3mon latest=now

Which is different to:
index=something earliest=-3mon@m latest=@m

Cheerz,
Björn

0 Karma

james_n
Path Finder

@skoelpin yes same data same timestamp from last one year onwards

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Can you post a screenshot of what you see and explain what you're looking to get?

Are you referring to different time spans as you extend the time period?

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Have you confirmed your timestamp is correct from 3 months ago?

0 Karma

adonio
Ultra Champion

timechart has auto spaning depends on the time picker
see here: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/timechart

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...