Splunk commands : Detail discussion on timechart command



In this video I have discussed about timechart command in Splunk.A timechart is a statistical aggregation applied to a field to produce a chart, with time used as the X-axis. You can specify a split-by field, where each distinct value of the split-by field becomes a series in the chart. If you use an eval expression, the split-by clause is required. With the limit and agg options, you can specify series filtering. These options are ignored if you specify an explicit where-clause. If you set limit=0, no series filtering occurs.

Materials used in this video can be downloaded from below repo,

Tutorials data :

source

6 thoughts on “Splunk commands : Detail discussion on timechart command”
  1. Hi.. I like your videoes.. i wan to learn Splunk.. Do you've any training materials which will suggest how to start from the beginning? Appreciate if you can share any Training material.

  2. Hi Sid, thanks for the video. One question about eval function. If eval is used as function, should the field be renamed ? little unclear on eval as a function. kindly explain and share any reference link for eval as function. I am unable to locate in splunk site. Thank you in advance sid.

  3. Hello,

    Can anyone help me on this:
    I have two kinds of events being pushed into two indexes in splunk:
    Events Type 1:

    index= "abc" source="access_combined" log_time=2020-04-06T08:46:12.480Z, component_name="validator"
    index= "abc" source="access_combined" log_time=2020-04-06T08:46:12.480Z, component_name="validator"
    index= "abc" source="access_combined" log_time=2020-04-06T08:46:13.480Z, component_name="validator"
    index= "abc" source="access_combined" log_time=2020-04-06T08:46:13.480Z, component_name="validator"
    index= "abc" source="access_combined" log_time=2020-04-06T08:46:14.480Z, component_name="validator"

    Events Type 2:
    index= "bcd" source="response_combined" log_time=2020-04-06T08:46:12.480Z, component_name="execute"
    index= "bcd" source="response_combined" log_time=2020-04-06T08:46:13.480Z, component_name="execute"
    index= "bcd" source="response_combined" log_time=2020-04-06T08:46:13.480Z, component_name="execute"
    index= "bcd" source="response_combined" log_time=2020-04-06T08:46:14.480Z, component_name="execute"

    Individually I have show in different graph with the below 2 commands:
    index= "abc" source="access_combined" | timechart count
    index= "bcd" source="response_combined" | timechart count

    Now i have to show the line representation of both the incoming event types in a single time chart:
    I want to represent the two above differnent line graphs into one single graph so that i can compare the number of input messages coming in each index through one timechart(line graph) representation.

    Please help me on this.

  4. How can we give span for month and it will sum the count on last day of every month ?
    I tries this "span=mon@mon-1d" but its now working .
    please help me to find the solution for this.

Leave a Reply

Your email address will not be published.

Captcha loading...