Splunk Search

How do I change the span based on the time picker selection using timechart?

james_n
Path Finder

HI,

I have a simple query i.e |timechart count by something

The span should change dynamically, for EX: if I select today, the span should be 1h — if I select last months span, it should be 1d — if i select the last 3 months' span, it should be 1mon,

|timechart span=$$ count by something. Plz help me on this.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Use timechart bins=40 to achieve your examples. It'll tell splunk to use 40 or fewer bins - 24 hours in a day, 48 half-hours, pick hours, etc.

JohnMurphyAus
Path Finder

Perfect. Thank you!

0 Karma

james_n
Path Finder

@FrankVI I have a one dashboard which consist of only one visualisation with one time picker. In timepicker if we select 2months, than in visualisation timechart span should be 1mon like that

0 Karma

FrankVl
Ultra Champion

What you describe is pretty much the standard behavior of the timechart command. Ar you running into specific situations where you would like to deviate from the automatically chosen span?
http://docs.splunk.com/Documentation/Splunk/7.2.1/SearchReference/Timechart#Default_time_spans

0 Karma

dkeck
Influencer
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...