Splunk Search

timechart not showing any result while tstat does

unitrium
Explorer

Hi ,

I'm trying to build a single value dashboard for certain metrics. I would like to put it in the form of a timechart so I can have a trend value.

However this search gives me no result :

 

 

 

| tstats `summariesonly` min(_time) as firstTime,max(_time) as lastTime,count from datamodel=Vulnerabilities.Vulnerabilities by Vulnerabilities.signature,Vulnerabilities.dest, Vulnerabilities.severity | `drop_dm_object_name("Vulnerabilities")` | where firstTime!=lastTime AND severity!="informational" | eval age=round((lastTime-firstTime)/86400) | timechart span=30d avg(age) by lastTime

 

 

 


Which is strange because I feel like this command is almost the same :

 

 

 

| tstats `summariesonly` min(_time) as firstTime,max(_time) as lastTime,count from datamodel=Vulnerabilities.Vulnerabilities by Vulnerabilities.signature,Vulnerabilities.dest, Vulnerabilities.severity | `drop_dm_object_name("Vulnerabilities")` | where firstTime!=lastTime AND severity!="informational" | eval age=round((lastTime-firstTime)/86400) | bucket lastTime span=30d | stats avg(age) by lastTime

 

 

 

And this one returns me the results that I want. Could anybody help me out getting a timechart out of this ?

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

timechart is looking to use _time so try

... | eval age=round((lastTime-firstTime)/86400) | eval _time=lastTime | timechart span=30d avg(age)

 

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

timechart is looking to use _time so try

... | eval age=round((lastTime-firstTime)/86400) | eval _time=lastTime | timechart span=30d avg(age)

 

Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...