Splunk Search

timestamp snap to 30 seconds

aaronkorn
Splunk Employee
Splunk Employee

We have events that are written every 30 seconds and we would like to display these events individually in a timechart with a span of 30 seconds. How would we adjust or snap the timestamp to every 30 seconds?

0 Karma

kristian_kolb
Ultra Champion
 ...| bucket _time span=30s | timechart span=30s ...

is what I think you're after.

/k

aaronkorn
Splunk Employee
Splunk Employee

Thanks. This is what I used before and it appears to be working fine. I was just concerned if the timestamps weren't exactly, for example 1:00:30 - 1:01:00 it wouldnt work because some of them vary by 1 second or 2.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...