Splunk Search

Timechart and Timepicker?

jgauthier
Contributor

I am running a search like so:

sourcetype="stuff here" | timechart span=1h sum(bytes) as Total by limit=10 username useother=f

Is it possible to change the span based on a timepicker?

For instance, if timepicker is 15 minutes, then my span should be like 3 minutes. If it's 30 days, then I want the span to be 1d, etc.

Maybe I need to use a different method?

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

If you simply omit the span in the timechart command, it will choose an appropriate interval. Similarly, instead of specifying a span, you can specify a maximum number of bins to split, e.g. try bins=40 instead of span=1h

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

If you simply omit the span in the timechart command, it will choose an appropriate interval. Similarly, instead of specifying a span, you can specify a maximum number of bins to split, e.g. try bins=40 instead of span=1h

jgauthier
Contributor

Perfect. Thank you!

0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...