88.3k views
3 votes
The timechart command buckets data in time intervals depending on:

User Hassan TBT
by
6.1k points

1 Answer

7 votes
Depending on the time range or time span selected.

You can always leverage the timechart command and its functions to better provide and identify more contexts to discrete data. As in the example below, with the timechart command, you will bucket the events first into 5-minute interval. This is well specified by the span parameter.


Index=main sourcetype=access_combined |eval kb=bytes/1024 | timechart span=5m




User Robertson
by
6.1k points