Hi everyone, I'm quite new to splunk. I'm trying to plot a graph using timechart with starting time of the event and the ending time of the event.
This is my search query:
sourcetype="Traffic" | stats earliest(_time) as startOfEvent latest(_time) as endOfEvent range(_time) as duration by Message
This is the return result from the query:
Message | startOfEvent | endOfEvent| duration
msg1 | 1368457298 | 1368459923 | 2625
msg2 | 1368457298 | 1368457821 | 523
How can i turn this into a timechart?
Any help is appreciated.
Thanks!
If you could include some metrics you would like, it might be easier to show you specifics. But the general format is:
sourcetype="Traffic" | timechart count by Message span=5m
This will show the count by Message over time.
http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/Timechart