Splunk Search

How do I change the interval of results displayed?

mattgates
Explorer

I am searching for results from a storage report that is generated once an hour. When I generate a a chart for these results, I see only data from 00:00 each day. I want the chart to display the hour by hour data. How do I change the interval of the results to be once hourly rather than once daily?

Tags (3)
0 Karma
1 Solution

southeringtonp
Motivator

It isn't 100% clear what you're trying to do, but it sounds like you may want to add span=1h to your chart command...

Have you looked at this page?

http://www.splunk.com/base/Documentation/latest/SearchReference/Chart

View solution in original post

southeringtonp
Motivator

It isn't 100% clear what you're trying to do, but it sounds like you may want to add span=1h to your chart command...

Have you looked at this page?

http://www.splunk.com/base/Documentation/latest/SearchReference/Chart

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...