Splunk Search
Highlighted

Why is the predict command projecting past dates in the future?

Engager

What I thought was going to be a simple search:

lucy
| eval UsedT=UsedMB/1024/1024 
| eval UsedTB=round(UsedT,1) 
| timechart avg(UsedTB) as TBUsed span=1w 
| predict TBUsed

But my graph is showing the current data, up to today (March 28th), then jumping back to February 1st.alt text
Any ideas?

0 Karma
Highlighted

Re: Why is the predict command projecting past dates in the future?

Builder

Odd.. could you post also the results table?

0 Karma
Highlighted

Re: Why is the predict command projecting past dates in the future?

Engager

Root cause was found. Turns out everything gets screwed up if there is missing data. In this case my data set was only about 90 days, and I was search for 120 days. The null data at the beginning screwed everything up.

0 Karma
Highlighted

Re: Why is the predict command projecting past dates in the future?

SplunkTrust
SplunkTrust

Please accept your answer so that the question will show as complete.

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.