Splunk Search

Getting rid of unused time in timechart

plucas_splunk
Splunk Employee
Splunk Employee

Given a search:

index="muni" | nbclosest | timechart span=30m dc(vehicle_id) as NumVehicles

(where nbclosest is a custom search command that filters results and isn't relevant to this question) it correctly charts the data, but the problem the data is only from a subset of hours in the day, e.g., 10am to 7pm. When plotting it, it looks like the attached image:

alt text

I'd like to change the chart so that the times outside 10am-7pm aren't displayed at all. It would be as if the chart were squished horizontally by removing midnight-10am and 7pm-midnight.

How can I do this?

0 Karma
1 Solution

sundareshr
Legend

See if add cont=f to the timechart command gives you the desired output.

View solution in original post

somesoni2
Revered Legend

Give this a try. You may loose the x-axis markers

index="muni" | nbclosest | bucket span=30m _time | stats dc(vehicle_id) as NumVehicles by _time
0 Karma

plucas_splunk
Splunk Employee
Splunk Employee

This produces the same result as adding cont=f but, oddly, says "0 events" on the left.

0 Karma

sundareshr
Legend

See if add cont=f to the timechart command gives you the desired output.

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...