Splunk Search

How do I change the interval of results displayed?

mattgates
Explorer

I am searching for results from a storage report that is generated once an hour. When I generate a a chart for these results, I see only data from 00:00 each day. I want the chart to display the hour by hour data. How do I change the interval of the results to be once hourly rather than once daily?

Tags (3)
0 Karma
1 Solution

southeringtonp
Motivator

It isn't 100% clear what you're trying to do, but it sounds like you may want to add span=1h to your chart command...

Have you looked at this page?

http://www.splunk.com/base/Documentation/latest/SearchReference/Chart

View solution in original post

southeringtonp
Motivator

It isn't 100% clear what you're trying to do, but it sounds like you may want to add span=1h to your chart command...

Have you looked at this page?

http://www.splunk.com/base/Documentation/latest/SearchReference/Chart

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...