Working With Time
Working With Time
Working With Time
25 January 2023
Working with Time
turn data into doing™ 2 Copyright © 2023 Splunk, Inc. All rights reserved | 25 January 2023
Course Goals
• Define the _time field
• Compare time modifier and time picker
• Use index-time based modifiers
• Convert UNIX time to human readable time
• Use the timewrap command with timechart
• Describe how time zones are processed
The timestamp is
directly derived from
the _time field
... latest=[+|-]<timeInt><timeUnit>@<timeUnit>
index=web sourcetype=access_combined
| stats sum(price) as totalSales by product_name
| bin totalSales bins=10
| stats list(product_name) as product_name by totalSales
| sort totalSales
| eval totalSales = "$".totalSales
<subseconds> us | ms | cd | ds
• Plots and trends data over time where _time is always the x-axis
• Results can be split by another <field> using a by clause
• The span and limit options control additional aspects of timechart
output and are discussed in succeeding slides
Note
The count function
returns a count of
all events or for a
specific field.
Note
Using timechart, you
can only split by one
field because _time is
the implied first by field.
A timechart creates
one data series
spanning 14 days
Note
The Failures_2weeks_before
series is truncated because the
timespan of the search is not
evenly divisible by the duration
specified by timewrap.
• Remember, date_* fields do not reflect your local time, but are
the values of time/date directly from the raw events
• To determine your time zone:
1. In Preferences, set Time Zone to Default System Timezone
2. Run a search over the last 15 minutes
3. Read the event timestamps and compare with your local time
Splunk Mobile
• Free app available to all Splunk Cloud
and Splunk Enterprise customers
• Analyze data and receive
actionable alerts on-the-go
with mobile-friendly dashboards
• iOS and Android
• See the Product Brief
• Download for iOS splk.it/ios
Splunk Core
Recommended
Splunk Enterprise
Prerequisite Certification(s): Splunk Core Certified User Exam Congratulations! You are a...
• None Time to study! We suggest candidates looking to prepare for
this exam complete Fundamentals 1 or the following courses:
Prerequisite Course(s): • What is Splunk?
• None • Intro to Splunk
• Using Fields
• Scheduling Reports and Alerts
• Visualizations
• Statistical Processing
• Working with Time Recommended Next Step
• Leveraging Lookups and Subsearches
• Splunk Core Certified Power User
• Search Optimization
• Enriching Data with Lookups
• Data Models
See here for registration assistance.
Prerequisite Certification(s): Splunk Core Certified Power User Exam Congratulations! You are a...
• None Time to study! We suggest candidates looking to prepare for
this exam complete Fundamentals 2 or the following courses:
Prerequisite Course(s): • Visualizations
• None • Statistical Processing
• Working with Time
• Comparing Values
• Result Modification
• Correlation Analysis
• Search Under the Hood Recommended Next Steps
• Introduction to Knowledge Objects
• Splunk Core Certified Advanced Power User
• Creating Knowledge Objects
• Creating Field Extractions • Splunk Enterprise Certified Admin
• Data Models
• Using Choropleth • Splunk Cloud Certified Admin
Prerequisite Certification(s): Splunk Core Certified Advanced Power User Exam Congratulations! You are a...
• Splunk Core Certified Power User Time to study! We suggest candidates looking to prepare for this exam
complete Fundamentals 3, Creating Dashboards, and Advanced
Searching & Reporting or the following courses:
Prerequisite Course(s):
• Using Fields
• None
• Working with Time
• Comparing Values
• Result Modification
• Leveraging Lookups and Subsearches
• Correlation Analysis
• Search Under the Hood Recommended Next Steps
• Multivalue Fields
• Splunk Enterprise Certified Admin
• Search Optimization
• Creating Field Extractions • Splunk Cloud Certified Admin
• Enriching Data with Lookups
• Data Models
• Using Choropleth
• Introduction to Dashboards
• Dynamic Dashboards
See here for registration assistance.
Working with Time
turn data into doing™ 67 Copyright © 2023 Splunk, Inc. All rights reserved | 25 January 2023
Splunk Cloud Certified Admin
This certification demonstrates an individual's ability to support the
day-to-day administration and health of a Splunk Cloud environment
Prerequisite Certification(s): Splunk Cloud Certified Admin Exam Congratulations! You are a...
• Splunk Core Certified Power User Time to study! We suggest candidates looking to
prepare for this exam complete either the Splunk
Prerequisite Course(s): Cloud Administration or the Transitioning to
Splunk Cloud course.
• None
Both courses will equally prepare candidates for
the exam, but are tailored to meet the needs of
the individual based on prior Splunk experience.
Prerequisite Certification(s): Splunk Enterprise Certified Admin Exam Congratulations! You are a...
• Splunk Core Certified Power User Time to study! We suggest candidates looking to
prepare for this exam complete the following courses:
Prerequisite Course(s):
• Splunk System Administration
• None • Splunk Data Administration
Prerequisite Certification(s): Splunk Enterprise Certified Architect Exam Congratulations! You are a...
• Splunk Core Certified Power User Time to study! We require candidates looking to register for
• Splunk Enterprise Certified Admin this exam to complete the following prerequisite courses:
• Architecting Splunk Enterprise Deployments
Prerequisite Course(s): • Troubleshooting Splunk Enterprise
• Splunk Cluster Administration
• Architecting Splunk Enterprise Deployments • Splunk Deployment Practical Lab
• Troubleshooting Splunk Enterprise
Candidates who are Splunk Enterprise Certified Admin
• Splunk Cluster Administration and have completed all of the above courses will automatically
• Splunk Deployment Practical Lab receive an exam authorization for the Splunk Enterprise Recommended Next Steps
Certified Architect exam within 5-7 business days of receiving
their passing lab results. • Splunk Core Certified Consultant
Prerequisite Certification(s): Splunk Core Certified Consultant Exam Congratulations! You are a...
• Splunk Core Certified Power User Time to study! We require candidates looking to register
• Splunk Enterprise Certified Admin for this exam to complete the following prerequisite
courses:
• Splunk Enterprise Certified Architect
• Fundamentals 3, Creating Dashboards, Advanced
Searching & Reporting*
Prerequisite Course(s): • Core Consultant Labs
• Advanced Power User courses or digital badge* • Services Core Implementation
• Core Consultant Labs Candidates who are Splunk Enterprise Certified
• Indexer Cluster Implementation Architects and have completed all of the above courses
must contact [email protected] to request their
• Distributed Search Migration Core Consultant exam authorization. Recommended Next Steps
• Implementation Fundamentals • None
See here for registration assistance.
• Architect Implementation 1-3 *These Advanced Power User courses can be replaced with a Splunk
Certified Advanced Power User badge or completion of the following
• Services Core Implementation courses: • Correlation Analysis
• Using Fields • Result Modification
• Creating Field Extractions • Multivalue Fields
• Enriching Data with Lookups • Search Under the Hood
• Data Models • Introduction to Dashboards
• Search Optimization • Dynamic Dashboards
• Working with Time • Using Choropleth
• Leveraging Lookups and Subsearches
• Comparing Values Working with Time
turn data into doing™ 71 Copyright © 2023 Splunk, Inc. All rights reserved | 25 January 2023
Splunk Certified Developer
This certification demonstrates an individual's expertise in drilldowns, advanced behaviors
and visualizations, planning, creating, and packaging apps, and REST endpoints
Prerequisite Certification(s): Splunk Certified Developer Exam Congratulations! You are a...
• Splunk Core Certified Power User Time to study! We suggest candidates looking
AND to prepare for this exam complete the
following courses:
• Splunk Enterprise Certified Admin
• Creating Dashboards with Splunk*
OR • Advanced Dashboards & Visualizations
• Splunk Cloud Certified Admin • Building Splunk Apps
• Developing with Splunk’s REST API
Prerequisite Course(s): This course may also be substituted with the Recommended Next Steps
• None following newly-launched courses:
• None
• Introduction to Dashboards
• Dynamic Dashboards
• Using Choropleth
See here for registration assistance.
Prerequisite Certification(s): Splunk IT Service Intelligence Certified Congratulations! You are a...
• None Admin Exam
Time to study! We suggest candidates looking to
Prerequisite Course(s): prepare for this exam complete the following
• None course:
• Implementing Splunk IT Service Intelligence
Prerequisite Certification(s): Splunk SOAR Certified Automation Congratulations! You are a...
• None Developer Exam
Time to study! We suggest candidates looking to
Prerequisite Course(s): prepare for this exam complete the following courses:
• None • Administering SOAR (Phantom)
• Developing SOAR (Phantom) Playbooks
• Advanced SOAR (Phantom) Implementation
Thank You