Deployment Architecture

Does bucket/bin command work from a lookup table/KVStore?

splunkrocks2014
Communicator

I have a timestamp column, my_time, stored in my kvstore, my_kv. I wanted to generate a report, but I got "No results found."

| inputlookup my_kv | bucket span=1h my_time | timechart count

I wonder if the bin/bucket command works for a lookup or kvstore. If not, are there other solutions? Thanks.

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

Yes, it does. All bin does is round down to the nearest specifier; there is no magic. The problem is that timechart in your case works only on _time so it is ignoring your my_time field. You need | rename my_time AS _time and then it will work.

View solution in original post

woodcock
Esteemed Legend

Yes, it does. All bin does is round down to the nearest specifier; there is no magic. The problem is that timechart in your case works only on _time so it is ignoring your my_time field. You need | rename my_time AS _time and then it will work.

splunkrocks2014
Communicator

Thank you very much!

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...