Splunk Search

charting time - using time within a lookup

brdr
Contributor

I have a lookup file with about 100K events. What I want to do is use timechart (span each day). There is a time field in the lookup called '_time'. I have:

| inputlookup mylookup.csv
| timechart span=1d sum(count)

Can I do this?

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

So what you want your query to do, show count of entries in the lookup per day or sum of some field's value? If you just want to see how many entries falls into a day, just use function count (no need to specify a field if just counting events).

 | inputlookup mylookup.csv 
 | convert timeformat="%Y-%m-%dT%H:%M:%S" mktime(_time) as _time
 | timechart span=1d count as Daily_Total

View solution in original post

0 Karma

somesoni2
Revered Legend

So what you want your query to do, show count of entries in the lookup per day or sum of some field's value? If you just want to see how many entries falls into a day, just use function count (no need to specify a field if just counting events).

 | inputlookup mylookup.csv 
 | convert timeformat="%Y-%m-%dT%H:%M:%S" mktime(_time) as _time
 | timechart span=1d count as Daily_Total
0 Karma

brdr
Contributor

ah man... thank you somesoni2!

0 Karma

niketn
Legend

@brdr if your issue is resolved, do accept the answer to mark this question as answered.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

somesoni2
Revered Legend

You can use timechart command as long as _time field in your lookup has date in epoch format. You can use sum(count) if there is a field count exists in the lookup.

0 Karma

brdr
Contributor

This is what I have. I do have a field called 'count' in my lookup that I don't care about. Here is my search:

| inputlookup mylookup.csv 
| convert timeformat="%Y-%m-%dT%H:%M:%S" mktime(_time) as _time
| rename count as count_c
| timechart span=1d sum(count) as Daily_Total

I see that _time is display the days, but Daily_Total is NULL (blank)??

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...