Splunk Search

Why does timechart not work?

Jaylon
Loves-to-Learn Lots

timechart [stats count|eval app=$A$|eval search=case(app=="*","span=30m count by B",app!="*","span=30m count by C")] is not work after upgrading splunk from 8.0.6 to 8.2.5. 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Something similar to this appears to work with 8.2.5 (and other versions). Please provide more details e.g. our dashboard SimpleXML as there may be something other than the timechart command not working.

0 Karma

tscroggins
Influencer

@Jaylon 

Can you provide more context? The search you provided isn't a functional standalone search in any version of Splunk.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...