Hello every body
I have been struggling with a serious problem recently
my splunk version is 7.2
when I use span Command (with tstats or bin ) , it starts from half hour ! instead of hour
for example :
| tstats count as count from datamodel=Log where Log.FinalStatus!=61 by _time span=1h
I have picture below as result , while I want time sections like 10 , 11, 12 ...
what should I do ??
Thank you
Does something like this work for you?
| tstats count as count from datamodel=Log where Log.FinalStatus!=61 by _time span=30m
| eval _time=_time-30*60
| bin _time span=1h
| eval _time=_time+30*60
| stats sum(count) as count by _time
Which timezone are you in?
Hi
+3:30
Does something like this work for you?
| tstats count as count from datamodel=Log where Log.FinalStatus!=61 by _time span=30m
| eval _time=_time-30*60
| bin _time span=1h
| eval _time=_time+30*60
| stats sum(count) as count by _time
It works 🙂
thank you 🙂
but do you know any solution to resolve this problem ?
I mean , every time this sections starts from hour , not half hour
_time is usually stored as number of second since start of epoch in utc - all span does is that the time value back to the start of the current time bucket (still in utc). When you display the time it is local format, hence the half hour boundary differences in your case. You could try displaying your times in utc or potentially make the adjustment when the events are indexed or petition your government to change their time zone settings so they align with hours rather than half past or move 😀