Splunk Search

Timechart and Timepicker?

jgauthier
Contributor

I am running a search like so:

sourcetype="stuff here" | timechart span=1h sum(bytes) as Total by limit=10 username useother=f

Is it possible to change the span based on a timepicker?

For instance, if timepicker is 15 minutes, then my span should be like 3 minutes. If it's 30 days, then I want the span to be 1d, etc.

Maybe I need to use a different method?

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

If you simply omit the span in the timechart command, it will choose an appropriate interval. Similarly, instead of specifying a span, you can specify a maximum number of bins to split, e.g. try bins=40 instead of span=1h

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

If you simply omit the span in the timechart command, it will choose an appropriate interval. Similarly, instead of specifying a span, you can specify a maximum number of bins to split, e.g. try bins=40 instead of span=1h

jgauthier
Contributor

Perfect. Thank you!

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...