Splunk Search

span with stats

vumanhtai
Path Finder

Hi ALL
i have a search
sourcetype="pan:traffic" | eval Byte_IN=bytes_in/1024/1024/1024 | eval Byte_OUT=bytes_out/1024/1024/1024 |eval SumByte=bytes/1024/1024/1024 | stats sum(Byte_IN) AS GB_IN ,sum(Byte_OUT) AS GB_OUT ,sum(SumByte) AS Sum_GB

i want span=1s
how can do that

Tags (2)
0 Karma
1 Solution

mayurr98
Super Champion

Hey you can use timechart command

sourcetype="pan:traffic" | eval Byte_IN=bytes_in/1024/1024/1024 | eval Byte_OUT=bytes_out/1024/1024/1024 |eval SumByte=bytes/1024/1024/1024 | timechart span=1s sum(Byte_IN) AS GB_IN ,sum(Byte_OUT) AS GB_OUT ,sum(SumByte) AS Sum_GB

Let me know if this helps you!

View solution in original post

micahkemp
Champion

There are multiple options. The first of which is timechart, as @mayurr98 posted above. The other, which you seem to have specifically asked about, is to do stats BY _time, where you have previously performed bin against _time:

sourcetype="pan:traffic" | eval Byte_IN=bytes_in/1024/1024/1024 | eval Byte_OUT=bytes_out/1024/1024/1024 |eval SumByte=bytes/1024/1024/1024 | bin span=1min _time | stats sum(Byte_IN) AS GB_IN ,sum(Byte_OUT) AS GB_OUT ,sum(SumByte) AS Sum_GB BY _time

Which of these is most appropriate depends on your specific use case, pick the style that gives you the type of results that work best for you.

0 Karma

mayurr98
Super Champion

Hey you can use timechart command

sourcetype="pan:traffic" | eval Byte_IN=bytes_in/1024/1024/1024 | eval Byte_OUT=bytes_out/1024/1024/1024 |eval SumByte=bytes/1024/1024/1024 | timechart span=1s sum(Byte_IN) AS GB_IN ,sum(Byte_OUT) AS GB_OUT ,sum(SumByte) AS Sum_GB

Let me know if this helps you!

vumanhtai
Path Finder

oh! yeah
thank you so much

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...