Splunk Search

Timechart using Subsearch to set Span

moogmusic
Path Finder

I'm trying to use a Subsearch to set the span parameter in timechart - other posts have suggested something like this:

| timechart [ stats count | addinfo | eval timerange=1593817200-1593730800
| eval span=case(timerange<=3600,"1m",timerange<=14400,"15m",timerange<=86400,"30m",timerange<=2592000,"1d",timerange>2592000,"1mon")
| return span ] sum(raw_len_gb) as GB by index cont=f

When. I run the search, I get no events matching. However if I expand the search (Ctrl+E) then it resolves to the expected value and the expanded search runs no problem.

Any ideas? Thanks

Labels (2)
0 Karma

to4kawa
Ultra Champion
index=_internal 
| timechart [|makeresults | eval query="span=10m"| return $query] count

That's interesting. I think it's better to send text.

0 Karma

moogmusic
Path Finder

Thanks for the suggestion but I'm not quite sure what you mean?

0 Karma

moogmusic
Path Finder

I tried what you suggest. and get the same result - the query matches no events but then if I expand it and run the expansion, it works fine.

0 Karma

to4kawa
Ultra Champion

I think your problem is macro settings, not your question.

0 Karma
Get Updates on the Splunk Community!

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...