Splunk Search

Why can't I plot timechart to investigate seasonality in index data?

POR160893
Builder

Hi,

I am running the following query to check seasonality in my index:
index="ABC
| timechart count by _time | timechart

Error in 'timechart' command: Repeated group-by field '_time'.
The search job has failed due to an error. You may be able view the job in the Job Inspector.However, I am receiving the following error and I do not understand it at all:

Can you please help?
Many thanks!

Labels (2)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @POR160893,

timechart has insede the command the grouping by _time so you don't need to explicitate it, in addition you cannot use timechart command without any function:

index="ABC
| timechart count

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...