Splunk Search

timestamp snap to 30 seconds

aaronkorn
Splunk Employee
Splunk Employee

We have events that are written every 30 seconds and we would like to display these events individually in a timechart with a span of 30 seconds. How would we adjust or snap the timestamp to every 30 seconds?

0 Karma

kristian_kolb
Ultra Champion
 ...| bucket _time span=30s | timechart span=30s ...

is what I think you're after.

/k

aaronkorn
Splunk Employee
Splunk Employee

Thanks. This is what I used before and it appears to be working fine. I was just concerned if the timestamps weren't exactly, for example 1:00:30 - 1:01:00 it wouldnt work because some of them vary by 1 second or 2.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...