Splunk Search

Getting rid of unused time in timechart

plucas_splunk
Splunk Employee
Splunk Employee

Given a search:

index="muni" | nbclosest | timechart span=30m dc(vehicle_id) as NumVehicles

(where nbclosest is a custom search command that filters results and isn't relevant to this question) it correctly charts the data, but the problem the data is only from a subset of hours in the day, e.g., 10am to 7pm. When plotting it, it looks like the attached image:

alt text

I'd like to change the chart so that the times outside 10am-7pm aren't displayed at all. It would be as if the chart were squished horizontally by removing midnight-10am and 7pm-midnight.

How can I do this?

0 Karma
1 Solution

sundareshr
Legend

See if add cont=f to the timechart command gives you the desired output.

View solution in original post

somesoni2
Revered Legend

Give this a try. You may loose the x-axis markers

index="muni" | nbclosest | bucket span=30m _time | stats dc(vehicle_id) as NumVehicles by _time
0 Karma

plucas_splunk
Splunk Employee
Splunk Employee

This produces the same result as adding cont=f but, oddly, says "0 events" on the left.

0 Karma

sundareshr
Legend

See if add cont=f to the timechart command gives you the desired output.

Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...