Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Bucket against field other than _time

$
0
0
Can I use the bucket command to group fields by time/date when extracted against a field other than _time? I have a field called pub date in this format; 2017-10-04 09:00:27 and was hoping the following would group the events into buckets of 6 hours; index=* | bucket pubdate span=6h | stats count by pub date Dosent seem to work, just lists all the individual events.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>