Splunk Search

Ingore last result in timechart

Ponczi1
Explorer

Hello i have a search query with timechart function but i don't want to display last bucket because it shows not complete data.
I use 5m span and i would like to display ONLY the time frames that have completely passed. Is there an easy way to achieve this?

Tags (2)
0 Karma
1 Solution

bmacias84
Champion

Timechart has a command option call partial. By default this is set to true, so set this to false. Only the first and last buckets can be partials. http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Timechart

...| timechart partial=False count by foo

View solution in original post

mayurr98
Super Champion

can you provide the timechart query that you have?

0 Karma

bmacias84
Champion

Timechart has a command option call partial. By default this is set to true, so set this to false. Only the first and last buckets can be partials. http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Timechart

...| timechart partial=False count by foo

cmerriman
Super Champion

this is a bit tedious, but should get you what you need.

....|<timechart>|reverse|streamstats count|search count>1|reverse
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...