Splunk Search

How to create a timechart with a time field?

Marco_Develops
Path Finder

I'm trying to make a time chart where it uses the time value specified in my table.  Rather than the default _time value.

Currently I'm trying something like this:

base search
|eval Failures = if(STATUS ="Failed",1,0)
| timechart sum(Failures) by TIME

DATE TIME  SYSTEM Failures
03/01/2022 12:00 Development 10
03/01/2022 13:00 Development 2
04/01/2022 15:00 Development 3
05/01/2022 18:00 Development 8

 

 Any suggestions help :-).

 

Thank you,

Marco

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
base search
| eval Failures = if(STATUS ="Failed",1,0)
| chart sum(Failures) by TIME

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
base search
| eval Failures = if(STATUS ="Failed",1,0)
| chart sum(Failures) by TIME
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

<P style=" text-align: center; "><span class="lia-inline-image-display-wrapper lia-image-align-center" ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

<FONT size="5"><FONT size="5" color="#FF00FF">Get the latest news and updates from the Splunk Community ...