Splunk Search

Timechart X Axis - Limiting the Time Range Plot

nibinabr
Communicator

I'm performing a search and plotting a timechart

index=hello_index sourcetype=hello_sourcetype event_id="001" now="12/16/2014:00:00:00" earliest="-1d@d" latest="+2d@d"| ...... |.....|
..| eval _time=time_stamp_I_calculated|timechart sum(something)

I have a search over 72 hrs because I don't exactly know when the event_id "001" happened. I modified _time so that it contains the timestamps of my interest during my search.

Problem
Timechart plots time on the x axis for the 72 hr window(from 15th Dec to 17th Dec).

Question
Is there a way to plot the Xaxis using time range of my interest (from the min value to the max value of _time) and not the 72 hr window.

Tags (1)

tachifelix
Path Finder

try something like this:

 .....|timechart span=1d cont=f sum(something)
0 Karma

somesoni2
Revered Legend

See the documentation on the timechart command here and see the option "cont".

http://docs.splunk.com/Documentation/Splunk/6.2.0/SearchReference/Timechart#Optional_arguments

Its defaults to true and forces timechart to span over the timerange. Making it false or f will trim your chart from min to max value of _time.

nibinabr
Communicator

I'm not exactly sure why cont didn't work well for me. I solved this issue by doing a sub search that returns the earliest and latest time and use that as the earliest and latest values for the parent search.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...