Splunk Search

timestamp snap to 30 seconds

aaronkorn
Splunk Employee
Splunk Employee

We have events that are written every 30 seconds and we would like to display these events individually in a timechart with a span of 30 seconds. How would we adjust or snap the timestamp to every 30 seconds?

0 Karma

kristian_kolb
Ultra Champion
 ...| bucket _time span=30s | timechart span=30s ...

is what I think you're after.

/k

aaronkorn
Splunk Employee
Splunk Employee

Thanks. This is what I used before and it appears to be working fine. I was just concerned if the timestamps weren't exactly, for example 1:00:30 - 1:01:00 it wouldnt work because some of them vary by 1 second or 2.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...