Splunk Search

## How to make a timechart by shift?

Engager

Hi all,

I am trying to create a timechart that divides the data by 12 hour shifts. I have
| timechart span = 12h (followed by all the data)

How do I make each span start at 0600 and 1800?

Thanks!

Labels (2)

• ### timechart

Tags (1)
1 Solution
SplunkTrust

Align your time period to 6pm for example

``earliest=-7d@d-6h``

Rather than using timechart, you could split it up into the different steps.

``````| bin span=12h _time
| xyseries _time group metric``````

However, this will align to midnight and noon, so make adjustments before and after

``````| eval _time=relative_time(_time,"-6h")
| bin span=12h _time
| eval _time=relative_time(_time,"+6h")
| xyseries _time group metric``````

SplunkTrust

Align your time period to 6pm for example

``earliest=-7d@d-6h``

Rather than using timechart, you could split it up into the different steps.

``````| bin span=12h _time
| xyseries _time group metric``````

However, this will align to midnight and noon, so make adjustments before and after

``````| eval _time=relative_time(_time,"-6h")
| bin span=12h _time
| eval _time=relative_time(_time,"+6h")
| xyseries _time group metric``````

Engager

That worked wonderfully, thank you. One thing though, for some reason the +-6 adjusted mine to 10am and pm. No worries though, I just made it +-2 and it worked. Probably has to do with time zone. Thanks again

Get Updates on the Splunk Community!

#### Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

#### .conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

#### Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...