Splunk Search

How to have Snap bin to last 5 minutes?

SMM10
Explorer

I want my search to consider a 5 minute timeframe. I have a stats with a bin for a span of 5 minutes but when running it sometimes it is split into two 5 minutes intervals. I want it to only consider 1 interval of 5 minutes. So right now I would snap to say 1:00-1:05 and 1:05-1:10. I would like it to just do something like 1:03-1:08; really whatever time it runs on I want that 5 minute span to be treated as one result set.

 

Labels (1)
Tags (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Use this in the bin command

| bin _time span=5m aligntime=@m
0 Karma

Roy_9
Motivator
0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...