Deployment Architecture

Does bucket/bin command work from a lookup table/KVStore?

splunkrocks2014
Communicator

I have a timestamp column, my_time, stored in my kvstore, my_kv. I wanted to generate a report, but I got "No results found."

| inputlookup my_kv | bucket span=1h my_time | timechart count

I wonder if the bin/bucket command works for a lookup or kvstore. If not, are there other solutions? Thanks.

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

Yes, it does. All bin does is round down to the nearest specifier; there is no magic. The problem is that timechart in your case works only on _time so it is ignoring your my_time field. You need | rename my_time AS _time and then it will work.

View solution in original post

woodcock
Esteemed Legend

Yes, it does. All bin does is round down to the nearest specifier; there is no magic. The problem is that timechart in your case works only on _time so it is ignoring your my_time field. You need | rename my_time AS _time and then it will work.

splunkrocks2014
Communicator

Thank you very much!

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...