There are a number of ways to calculate events per some period of time. All these techniques rely on rounding
_time down to some period of time, and then grouping the results by the rounded buckets of
The simplest approach to counting events over time is simply to use
timechart, like this:
sourcetype=impl_splunk_gen network=prod | timechart span=1m count
In the table view, we see the following:
Charts in Splunk do not attempt to show more points than the pixels present on the screen. The user is, instead, expected to change the number of points to graph, using the
span attributes. Calculating ...