I used timechart
command to display 1 hour intervals data. I am getting results starting from 00:00 with 1 hour interval. How I can display results with span=1h but 30th minute start time, like 1:30-2:30, 2:30 to 3:30 etc.
I dont think there is any straight way to do that. Try this workaround
your base search | eval _time=_time-1800 | timechart span=1h ...whatever you've... | eval _time=_time+1800
I dont think there is any straight way to do that. Try this workaround
your base search | eval _time=_time-1800 | timechart span=1h ...whatever you've... | eval _time=_time+1800