Splunk Search

Timechart time

darksky21
Path Finder

Hi i have a timechart

| timechart count by serial_number

is there a way to change the use of _time to another date field?

Tags (1)

norbert_hamel
Communicator

yes, you can use any other field which contains a time information:

| eval _time=MyTime

If MyTime is a text string, you can use strptime to convert the string to time. For example, if the MyTime is "03-22-2013 11:55":

| eval MyTimeDate=strptime(MyTime,"%m-%d-%Y %H:%M") | eval _time=MyTime

Ayn
Legend

Sure. timechart is, more or less, an alias for bucket _time | chart <functions> over _time so if you want to use another field, just do

`bucket yourfield | chart <functions> over yourfield`
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...