Splunk Search

How to have Snap bin to last 5 minutes?

SMM10
Explorer

I want my search to consider a 5 minute timeframe. I have a stats with a bin for a span of 5 minutes but when running it sometimes it is split into two 5 minutes intervals. I want it to only consider 1 interval of 5 minutes. So right now I would snap to say 1:00-1:05 and 1:05-1:10. I would like it to just do something like 1:03-1:08; really whatever time it runs on I want that 5 minute span to be treated as one result set.

 

Labels (1)
Tags (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Use this in the bin command

| bin _time span=5m aligntime=@m
0 Karma

Roy_9
Motivator
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...