Splunk Search

How to use timechart with stats and eval command

sunnyparmar
Communicator

Hi,

My query is below -

index=abc sourcetype=xyz Unable to connect to the remote server | Stats count(eval("Unable to connect to the remote server")) as "Error" by host

In this query how can I use (timechart span=1h) function? Any suggestions would be appreciated..

Thanks

Tags (3)
0 Karma
1 Solution

woodcock
Esteemed Legend

Your eval is wrong and redundant; try this:

index=abc sourcetype=xyz Unable to connect to the remote server | timechart span=1h count AS "Error" by host

View solution in original post

woodcock
Esteemed Legend

Your eval is wrong and redundant; try this:

index=abc sourcetype=xyz Unable to connect to the remote server | timechart span=1h count AS "Error" by host

sunnyparmar
Communicator

thanks... that's cool..

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...