Splunk Search

Count Events, Group by date field

hogan24
Path Finder

I have data that looks like this that I'm pulling from a db. Each row is pulling in as one event:
trxn_id create_dt_tm
123456 2013-11-22 11:01:22.xxx
123457 2013-11-22 11:01:23.xxx
123458 2013-11-22 11:01:24.xxx
123459 2013-11-22 11:02:22.xxx
123460 2013-11-22 11:02:22.xxx

I'd like the results to look like this in a timechart:
Time Count
2013-11-22 11:01 3
2013-11-22 11:02 2
etc

When I do something like this below, I'm getting the results in minute but they are grouped by the time in which they were indexed.
"index=main | timechart count(edi_trxn_detail_id) span=1m"

How do I tell splunk to group by the create_dt_tm of the transaction and subsequently by minute? Thanks.

0 Karma
1 Solution

hogan24
Path Finder

I think I may have figured this one out through suggestions and trial and error...

create_dt_tm | convert timeformat="%m/%d/%y %H:%M" ctime(create_dt_tm) as Minute | stats count as "Transactions" by Minute

This gives me the following which is what I was looking for. Thanks to those who helped!
Minute Transactions
11/24/13 10:00 8
11/24/13 10:01 6
11/24/13 10:02 4
etc

View solution in original post

0 Karma

hogan24
Path Finder

I think I may have figured this one out through suggestions and trial and error...

create_dt_tm | convert timeformat="%m/%d/%y %H:%M" ctime(create_dt_tm) as Minute | stats count as "Transactions" by Minute

This gives me the following which is what I was looking for. Thanks to those who helped!
Minute Transactions
11/24/13 10:00 8
11/24/13 10:01 6
11/24/13 10:02 4
etc

0 Karma

somesoni2
Revered Legend

Try following

index=main sourcetype=yoursourcetype| eval create_dt_tm=strptime(create_dt_tm,"%Y-%m-%d %H:%M") | stats count by create_dt_tm | eval create_dt_tm=strftime(create_dt_tm,"%Y-%m-%d %H:%M")
0 Karma

rechteklebe
Path Finder

You could extract the values until the minutes in create_dt_tm field by using Rex Command.
With the New field you can simply make a timechart span=1m count by "newfield".

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...