Calculating events per slice of time
There are a number of ways to calculate events per some period of time. All of these techniques rely on rounding
_time down to some period of time, and then grouping the results by the rounded "buckets" of
The simplest approach to count events over time is simply to use
timechart, like this:
sourcetype=impl_splunk_gen | timechart span=1m count
In table view, we see:
Looking at a 24-hour period, we are presented with 1,440 rows, one per minute.
Charts in Splunk do not attempt to show more points than the pixels present on the screen. The user is instead expected to change the number of points ...