Splunk Search

timestamp snap to 30 seconds

aaronkorn
Splunk Employee
Splunk Employee

We have events that are written every 30 seconds and we would like to display these events individually in a timechart with a span of 30 seconds. How would we adjust or snap the timestamp to every 30 seconds?

0 Karma

kristian_kolb
Ultra Champion
 ...| bucket _time span=30s | timechart span=30s ...

is what I think you're after.

/k

aaronkorn
Splunk Employee
Splunk Employee

Thanks. This is what I used before and it appears to be working fine. I was just concerned if the timestamps weren't exactly, for example 1:00:30 - 1:01:00 it wouldnt work because some of them vary by 1 second or 2.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...