Splunk Search

span with stats

vumanhtai
Path Finder

Hi ALL
i have a search
sourcetype="pan:traffic" | eval Byte_IN=bytes_in/1024/1024/1024 | eval Byte_OUT=bytes_out/1024/1024/1024 |eval SumByte=bytes/1024/1024/1024 | stats sum(Byte_IN) AS GB_IN ,sum(Byte_OUT) AS GB_OUT ,sum(SumByte) AS Sum_GB

i want span=1s
how can do that

Tags (2)
0 Karma
1 Solution

mayurr98
Super Champion

Hey you can use timechart command

sourcetype="pan:traffic" | eval Byte_IN=bytes_in/1024/1024/1024 | eval Byte_OUT=bytes_out/1024/1024/1024 |eval SumByte=bytes/1024/1024/1024 | timechart span=1s sum(Byte_IN) AS GB_IN ,sum(Byte_OUT) AS GB_OUT ,sum(SumByte) AS Sum_GB

Let me know if this helps you!

View solution in original post

micahkemp
Champion

There are multiple options. The first of which is timechart, as @mayurr98 posted above. The other, which you seem to have specifically asked about, is to do stats BY _time, where you have previously performed bin against _time:

sourcetype="pan:traffic" | eval Byte_IN=bytes_in/1024/1024/1024 | eval Byte_OUT=bytes_out/1024/1024/1024 |eval SumByte=bytes/1024/1024/1024 | bin span=1min _time | stats sum(Byte_IN) AS GB_IN ,sum(Byte_OUT) AS GB_OUT ,sum(SumByte) AS Sum_GB BY _time

Which of these is most appropriate depends on your specific use case, pick the style that gives you the type of results that work best for you.

0 Karma

mayurr98
Super Champion

Hey you can use timechart command

sourcetype="pan:traffic" | eval Byte_IN=bytes_in/1024/1024/1024 | eval Byte_OUT=bytes_out/1024/1024/1024 |eval SumByte=bytes/1024/1024/1024 | timechart span=1s sum(Byte_IN) AS GB_IN ,sum(Byte_OUT) AS GB_OUT ,sum(SumByte) AS Sum_GB

Let me know if this helps you!

vumanhtai
Path Finder

oh! yeah
thank you so much

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...