Splunk Search

How to plot the max of a value in 1 minute intervals over a period for an extracted field?

sankalpsah
New Member

Hi,

I am very new to Splunk. I have extracted a value from my data. The value appears every 25 seconds. I want to plot the max of that value over a time interval of 1 min.

For example:
time 0 val 5
time 25 val 3
time 50 val 10
time 75 val 2
....

i want for time 0 max will be 10 and for time 60 max will be say 2 and so on.

I want to plot this max value with time (0, 60, 120 seconds etc).

Any help is appreciated.

Thanks.

0 Karma
1 Solution

woodcock
Esteemed Legend

Like this:

... | timechart span=1m max(val)

View solution in original post

woodcock
Esteemed Legend

Like this:

... | timechart span=1m max(val)
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...