Splunk Search

charting time - using time within a lookup

brdr
Contributor

I have a lookup file with about 100K events. What I want to do is use timechart (span each day). There is a time field in the lookup called '_time'. I have:

| inputlookup mylookup.csv
| timechart span=1d sum(count)

Can I do this?

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

So what you want your query to do, show count of entries in the lookup per day or sum of some field's value? If you just want to see how many entries falls into a day, just use function count (no need to specify a field if just counting events).

 | inputlookup mylookup.csv 
 | convert timeformat="%Y-%m-%dT%H:%M:%S" mktime(_time) as _time
 | timechart span=1d count as Daily_Total

View solution in original post

0 Karma

somesoni2
Revered Legend

So what you want your query to do, show count of entries in the lookup per day or sum of some field's value? If you just want to see how many entries falls into a day, just use function count (no need to specify a field if just counting events).

 | inputlookup mylookup.csv 
 | convert timeformat="%Y-%m-%dT%H:%M:%S" mktime(_time) as _time
 | timechart span=1d count as Daily_Total
0 Karma

brdr
Contributor

ah man... thank you somesoni2!

0 Karma

niketn
Legend

@brdr if your issue is resolved, do accept the answer to mark this question as answered.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

somesoni2
Revered Legend

You can use timechart command as long as _time field in your lookup has date in epoch format. You can use sum(count) if there is a field count exists in the lookup.

0 Karma

brdr
Contributor

This is what I have. I do have a field called 'count' in my lookup that I don't care about. Here is my search:

| inputlookup mylookup.csv 
| convert timeformat="%Y-%m-%dT%H:%M:%S" mktime(_time) as _time
| rename count as count_c
| timechart span=1d sum(count) as Daily_Total

I see that _time is display the days, but Daily_Total is NULL (blank)??

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...