Splunk Search

How to graph values using timechart?

tgow
Splunk Employee
Splunk Employee

Here is a snippet from my logfile:

Mar 24 01:31:11,388  INFO [0x41401960]: NoSnmpMibInstance: CountWorker.ProcLoTimes = 11628^8861^1.31^0^291

I want to pull the number in between the 2nd and 3rd caret, create field called "plavg" and graph the values along the X axis:

| rex field=_raw "CountWorker.ProcLoTimes\s+=\s+\d+\^\d+\^(?<plavg>[^\^]+)" | timechart values(plavg)

The regex is working but the timechart is not. How do I graph the values from my logfile on a timechart? Do I have to convert the "1.31" from a string to a number?

Thanks in advance.

Tags (1)
0 Karma
1 Solution

tgow
Splunk Employee
Splunk Employee

Timechart was putting the data into 10 minute buckets by default and the time interval for the events was less than a minute. This resulted in multiple values per time interval so it wouldn't graph. Here is search that worked:

| rex field=_raw "CountWorker.ProcLoTimes\s+=\s+\d+\^\d+\^(?[^\^]+)" | timechart span=30s values(plavg)

You have to use values because timechart needs a function before the field.

View solution in original post

tgow
Splunk Employee
Splunk Employee

Timechart was putting the data into 10 minute buckets by default and the time interval for the events was less than a minute. This resulted in multiple values per time interval so it wouldn't graph. Here is search that worked:

| rex field=_raw "CountWorker.ProcLoTimes\s+=\s+\d+\^\d+\^(?[^\^]+)" | timechart span=30s values(plavg)

You have to use values because timechart needs a function before the field.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...