Splunk Search

Can I just do a timewrap on just 1 field/column?

HattrickNZ
Motivator

docs http://docs.splunk.com/Documentation/Splunk/6.5.0/SearchReference/Timewrap

Can I just do a timewrap on just 1 field/column?
e.g. .... search | timewrap column1 d series=exact

I have a search that gives me 3 cloumns - _time column 1 and column 2. I just want to do a timewrap on column1 and leave column 2 as is?

Let me know if more info is required.

Tags (1)
0 Karma

kaitlyngarratle
Engager

https://docs.splunk.com/Documentation/Splunk/7.1.0/SearchReference/Timewrap

so this says what you would do
| timechart field span=1d| timewrap 1week

HattrickNZ
Motivator

1week here will give "Each table column, which is the series, is 1 week of time.", or 1day or d will give you a column of 1 day worth of values.
| timechart field span=1d| timewrap 1week

my example is: .... timechart spand=h sum(kpi1) as column1 sum(kpi2) as column2 | timewrap column1 d series=exact

I just want to do the timewrap on column1. I don't think it can be done based on the docs.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...