Splunk Search

How do I change the span based on the time picker selection using timechart?

james_n
Path Finder

HI,

I have a simple query i.e |timechart count by something

The span should change dynamically, for EX: if I select today, the span should be 1h — if I select last months span, it should be 1d — if i select the last 3 months' span, it should be 1mon,

|timechart span=$$ count by something. Plz help me on this.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Use timechart bins=40 to achieve your examples. It'll tell splunk to use 40 or fewer bins - 24 hours in a day, 48 half-hours, pick hours, etc.

JohnMurphyAus
Path Finder

Perfect. Thank you!

0 Karma

james_n
Path Finder

@FrankVI I have a one dashboard which consist of only one visualisation with one time picker. In timepicker if we select 2months, than in visualisation timechart span should be 1mon like that

0 Karma

FrankVl
Ultra Champion

What you describe is pretty much the standard behavior of the timechart command. Ar you running into specific situations where you would like to deviate from the automatically chosen span?
http://docs.splunk.com/Documentation/Splunk/7.2.1/SearchReference/Timechart#Default_time_spans

0 Karma

dkeck
Influencer
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...