Splunk Search

Splitting multiple unknown fields to timechart by another field

cphair
Builder

Hi,

I've been using * in statistical commands for shorthand in writing out the fields. This has been useful on dynamic dashboards where I don't know what source/sourcetype a user will choose, so I don't have to specify field names ahead of time. A format like the following works:


index=internal | timechart avg(*) as avg*

but this one returns no results:

index=internal | timechart avg(*) as avg* by host

I'm guessing the * is eating the host field before the timechart command tries to split by it. Is there anything I can do about this? I'm running 4.3.4.

0 Karma

rechteklebe
Path Finder

Try this:

index=internal | timechart avg() as "avg" by host

0 Karma

cphair
Builder

Doesn't work. Same problem.

0 Karma

rechteklebe
Path Finder

the stars are filtered out..so for sure with the stars 😉

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...