| bin span=5min _time
try bin to aggregate on each time span.
| timechart span=15min count
However, timechart can be aggregated on any time span.
If you only count the event, here is fastest way:
| tstats count where index=your sourcetype=yours by _time span=15min
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Bin
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Timechart
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Tstats
... View more