Splunk Search

Timechart using Subsearch to set Span

moogmusic
Path Finder

I'm trying to use a Subsearch to set the span parameter in timechart - other posts have suggested something like this:

| timechart [ stats count | addinfo | eval timerange=1593817200-1593730800
| eval span=case(timerange<=3600,"1m",timerange<=14400,"15m",timerange<=86400,"30m",timerange<=2592000,"1d",timerange>2592000,"1mon")
| return span ] sum(raw_len_gb) as GB by index cont=f

When. I run the search, I get no events matching. However if I expand the search (Ctrl+E) then it resolves to the expected value and the expanded search runs no problem.

Any ideas? Thanks

Labels (2)
0 Karma

to4kawa
Ultra Champion
index=_internal 
| timechart [|makeresults | eval query="span=10m"| return $query] count

That's interesting. I think it's better to send text.

0 Karma

moogmusic
Path Finder

Thanks for the suggestion but I'm not quite sure what you mean?

0 Karma

moogmusic
Path Finder

I tried what you suggest. and get the same result - the query matches no events but then if I expand it and run the expansion, it works fine.

0 Karma

to4kawa
Ultra Champion

I think your problem is macro settings, not your question.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...