Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How can I Filter search results to only show sequential time buckets?

$
0
0
I have the need to filter the results of my search to only show 30 minutes of consecutive 5 minute time buckets. In other words, 6 consecutive time buckets. Example of results I want to see _time Event 9:00 am. My event 9:05 am. My event 9:10 am. My event 9:15 am. My event 9:20 am My event 9:25 am. My event But, I do not want to show any results of it is like below _time. Event 6:35 am. My event 6:40 am My event 9:05 am. My event 9:10 am My event Also one additional caveat. It is possible that my results could show 6 sequential buckets and more events that are not sequential because my time range is 12 hours. In this case o want to cut out the non sequential buckets and only display of there are 6 sequential buckets.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>