Splunk Search

How to reduce TimeChart count by minute if bins > x?

subtrakt
Contributor

Hi Everyone,

Would like to reduce bin count to 1 for each bin if total bins is greater than 10. (basically I want to flatline a timechart if a trend last longer than 10 minutes)

Here's what I came up with but it's not changing the counts. This will show the timecount in the legend but still can't get it to decrease real count to 1 if bins are > 10

Query:

| bin span=1m  _time | eventstats dc(_time) AS TIMECOUNT by host TYPE  | eval TYPE=host." ".TYPE." 

    | TIMECOUNT=".TIMECOUNT | timechart span=1m count(eval(if(TIMECOUNT>10,count=1,count))) by TYPE limit=0
Tags (3)
0 Karma
1 Solution

somesoni2
Revered Legend

Give this a try

your base search
| bucket span=1m _time | stats count by _time host TYPE 
| eval TYPE=host." ".TYPE."  
| eventstats dc(_time) AS TIMECOUNT by TYPE 
| eval count=if(TIMECOUNT>10,1,count)
| timechart span=1m sum(count) by TYPE limit=0

View solution in original post

0 Karma

somesoni2
Revered Legend

Give this a try

your base search
| bucket span=1m _time | stats count by _time host TYPE 
| eval TYPE=host." ".TYPE."  
| eventstats dc(_time) AS TIMECOUNT by TYPE 
| eval count=if(TIMECOUNT>10,1,count)
| timechart span=1m sum(count) by TYPE limit=0
0 Karma

subtrakt
Contributor

That works. Thanks!

0 Karma

subtrakt
Contributor

Added host to eventstats and looks like its working now and keeping the TYPE > 10 bins at 1, everything else normal count. Thanks again!

0 Karma

subtrakt
Contributor

Apologies.

Just realized it works but every other TYPE = 1 also. The stuff > 10 buckets should be 1 everything else should keep its original count.

0 Karma

ssadanala1
Contributor

can you elaborate your use case

0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...