Splunk Search

Help with Timechart function.

edsanchez07
New Member

Hi Community, 

I am trying to generate a timechart by month with the following query: 

index=xyz Question="zzz" NOT "Could not get results" NOT "No Deployment Results Found" NOT "No Matching Deployments Found" NOT "Unable to load PatchLib" | sort Computer_Name, patchmeantime | stats max(patchmeantime) as MaxAge by Computer_Name | stats avg(MaxAge) as MTTP
| timechart span=1mon avg(MTTP)


But nothing is showing up, so I am pretty sure I am missing something critical or super simple here but not sure what it is.....

Any help will be really appreciated. 

Labels (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Your query is ultimately looking to show a single figure per month of avg(MTTP), which is an average of a maximum

The way to do this is like this

index=xyz Question="zzz" NOT "Could not get results" NOT "No Deployment Results Found" NOT "No Matching Deployments Found" NOT "Unable to load PatchLib" 
| bin _time span=1mon
| stats max(patchmeantime) as MaxAge by _time Computer_Name 
| timechart span=1mon avg(MaxAge) as MTTP

This will bucket _time by 1 month and then the stats by _time will calculate the max age for each computer for each month. Then the timechart will calculate that average for all max values in the month.

Note: Do not sort - in this case it has no purpose. In the general case, sort ONLY when necessary and as late as possible in the pipeline.

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The timechart command requires the _time field, but that field was discarded by the stats commands.  The easiest fix is to replace stats with eventstats.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...