Splunk Search

how can i dynamicly change span parametr in timechart

mishaaaaaaaaaa
Explorer

i need to change span parameter depending on the time range
how can i set dynamycly changing of span in my search query?
or if it's impossible how can i set my span parameter like this:
.....
| eval spanValue=floor(0.0541/15*900)
| eval unit="m@m"
| eval spanConcatinated=spanValue."".unit
| timechart span=spanConcatinated
.....

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

mishaaaaaaaaaa
Explorer

thanks a lot!

0 Karma

woodcock
Esteemed Legend

Don't forget to UpVote!

0 Karma

mishaaaaaaaaaa
Explorer

Thanks a lot! that's what i was looking for!

0 Karma

woodcock
Esteemed Legend

While we certainly appreciate your UpVotes here, @mishaaaaaaaaaa, I was talking about the other Answers inside the links that we referenced. The reason that this is important, is so that others will be more easily able to find the answers straight away and not have to post duplicate questions like you did (having not been able to find the other Q&As when searching).

0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...