Splunk Search

How do I change the span based on the time picker selection using timechart?

james_n
Path Finder

HI,

I have a simple query i.e |timechart count by something

The span should change dynamically, for EX: if I select today, the span should be 1h — if I select last months span, it should be 1d — if i select the last 3 months' span, it should be 1mon,

|timechart span=$$ count by something. Plz help me on this.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Use timechart bins=40 to achieve your examples. It'll tell splunk to use 40 or fewer bins - 24 hours in a day, 48 half-hours, pick hours, etc.

JohnMurphyAus
Path Finder

Perfect. Thank you!

0 Karma

james_n
Path Finder

@FrankVI I have a one dashboard which consist of only one visualisation with one time picker. In timepicker if we select 2months, than in visualisation timechart span should be 1mon like that

0 Karma

FrankVl
Ultra Champion

What you describe is pretty much the standard behavior of the timechart command. Ar you running into specific situations where you would like to deviate from the automatically chosen span?
http://docs.splunk.com/Documentation/Splunk/7.2.1/SearchReference/Timechart#Default_time_spans

0 Karma

dkeck
Influencer
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...