Splunk Search

Why is the predict command projecting past dates in the future?

ajtalbot1
Engager

What I thought was going to be a simple search:

lucy
| eval UsedT=UsedMB/1024/1024 
| eval UsedTB=round(UsedT,1) 
| timechart avg(UsedTB) as TBUsed span=1w 
| predict TBUsed

But my graph is showing the current data, up to today (March 28th), then jumping back to February 1st.alt text
Any ideas?

0 Karma

ajtalbot1
Engager

Root cause was found. Turns out everything gets screwed up if there is missing data. In this case my data set was only about 90 days, and I was search for 120 days. The null data at the beginning screwed everything up.

0 Karma

DalJeanis
Legend

Please accept your answer so that the question will show as complete.

0 Karma

gfreitas
Builder

Odd.. could you post also the results table?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...