Splunk Search

Splitting multiple unknown fields to timechart by another field

cphair
Builder

Hi,

I've been using * in statistical commands for shorthand in writing out the fields. This has been useful on dynamic dashboards where I don't know what source/sourcetype a user will choose, so I don't have to specify field names ahead of time. A format like the following works:


index=internal | timechart avg(*) as avg*

but this one returns no results:

index=internal | timechart avg(*) as avg* by host

I'm guessing the * is eating the host field before the timechart command tries to split by it. Is there anything I can do about this? I'm running 4.3.4.

0 Karma

rechteklebe
Path Finder

Try this:

index=internal | timechart avg() as "avg" by host

0 Karma

cphair
Builder

Doesn't work. Same problem.

0 Karma

rechteklebe
Path Finder

the stars are filtered out..so for sure with the stars 😉

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...