Splunk Search
Highlighted

How to display a table with time interval of 1 hour, starting at the 30 minute mark?

Contributor

I used timechart command to display 1 hour intervals data. I am getting results starting from 00:00 with 1 hour interval. How I can display results with span=1h but 30th minute start time, like 1:30-2:30, 2:30 to 3:30 etc.

0 Karma
Highlighted

Re: How to display a table with time interval of 1 hour, starting at the 30 minute mark?

SplunkTrust
SplunkTrust

I dont think there is any straight way to do that. Try this workaround

your base search | eval _time=_time-1800 | timechart span=1h ...whatever you've... | eval _time=_time+1800

View solution in original post