Splunk Search

Timechart time

darksky21
Path Finder

Hi i have a timechart

| timechart count by serial_number

is there a way to change the use of _time to another date field?

Tags (1)

norbert_hamel
Communicator

yes, you can use any other field which contains a time information:

| eval _time=MyTime

If MyTime is a text string, you can use strptime to convert the string to time. For example, if the MyTime is "03-22-2013 11:55":

| eval MyTimeDate=strptime(MyTime,"%m-%d-%Y %H:%M") | eval _time=MyTime

Ayn
Legend

Sure. timechart is, more or less, an alias for bucket _time | chart <functions> over _time so if you want to use another field, just do

`bucket yourfield | chart <functions> over yourfield`
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...