Splunk Search

How do I change the span based on the time picker selection using timechart?

james_n
Path Finder

HI,

I have a simple query i.e |timechart count by something

The span should change dynamically, for EX: if I select today, the span should be 1h — if I select last months span, it should be 1d — if i select the last 3 months' span, it should be 1mon,

|timechart span=$$ count by something. Plz help me on this.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Use timechart bins=40 to achieve your examples. It'll tell splunk to use 40 or fewer bins - 24 hours in a day, 48 half-hours, pick hours, etc.

JohnMurphyAus
Path Finder

Perfect. Thank you!

0 Karma

james_n
Path Finder

@FrankVI I have a one dashboard which consist of only one visualisation with one time picker. In timepicker if we select 2months, than in visualisation timechart span should be 1mon like that

0 Karma

FrankVl
Ultra Champion

What you describe is pretty much the standard behavior of the timechart command. Ar you running into specific situations where you would like to deviate from the automatically chosen span?
http://docs.splunk.com/Documentation/Splunk/7.2.1/SearchReference/Timechart#Default_time_spans

0 Karma

dkeck
Influencer
0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...