Splunk Search

Data results not aligning with time

plapila
Explorer

Been experimenting with ML toolkit and having some weird issues. I can get nice predictions by teaching the data but when trying to visulize and show the data on a table I get some issues. The data and the prediction don't seem to align by time even thou the time field is same.

 

splunk_data_align.jpg

Labels (1)
Tags (2)
0 Karma
1 Solution

plapila
Explorer

I was able to correct this by using chart instead of timechart

 


@plapila wrote:

@ITWhisperer wrote:

What was the SPL you used to produce this?


index=fav  AND ACTION="Modem boot" | bin _time span=1d | timechart count by ACTION | apply Modemboot

 


index=fav AND ACTION="Modem boot"
| bin _time span=1d | chart count(ACTION) as "Modem boot" by _time span=1d cont=true | apply Modemboot

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What was the SPL you used to produce this?

0 Karma

plapila
Explorer

@ITWhisperer wrote:

What was the SPL you used to produce this?


index=fav  AND ACTION="Modem boot" | bin _time span=1d | timechart count by ACTION | apply Modemboot

 

0 Karma

plapila
Explorer

I was able to correct this by using chart instead of timechart

 


@plapila wrote:

@ITWhisperer wrote:

What was the SPL you used to produce this?


index=fav  AND ACTION="Modem boot" | bin _time span=1d | timechart count by ACTION | apply Modemboot

 


index=fav AND ACTION="Modem boot"
| bin _time span=1d | chart count(ACTION) as "Modem boot" by _time span=1d cont=true | apply Modemboot

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...