Splunk Search

Help with Timechart function.

edsanchez07
New Member

Hi Community, 

I am trying to generate a timechart by month with the following query: 

index=xyz Question="zzz" NOT "Could not get results" NOT "No Deployment Results Found" NOT "No Matching Deployments Found" NOT "Unable to load PatchLib" | sort Computer_Name, patchmeantime | stats max(patchmeantime) as MaxAge by Computer_Name | stats avg(MaxAge) as MTTP
| timechart span=1mon avg(MTTP)


But nothing is showing up, so I am pretty sure I am missing something critical or super simple here but not sure what it is.....

Any help will be really appreciated. 

Labels (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Your query is ultimately looking to show a single figure per month of avg(MTTP), which is an average of a maximum

The way to do this is like this

index=xyz Question="zzz" NOT "Could not get results" NOT "No Deployment Results Found" NOT "No Matching Deployments Found" NOT "Unable to load PatchLib" 
| bin _time span=1mon
| stats max(patchmeantime) as MaxAge by _time Computer_Name 
| timechart span=1mon avg(MaxAge) as MTTP

This will bucket _time by 1 month and then the stats by _time will calculate the max age for each computer for each month. Then the timechart will calculate that average for all max values in the month.

Note: Do not sort - in this case it has no purpose. In the general case, sort ONLY when necessary and as late as possible in the pipeline.

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The timechart command requires the _time field, but that field was discarded by the stats commands.  The easiest fix is to replace stats with eventstats.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...