timewrap command usage
You must use the timechart
command in the search before you use the timewrap
command.
The wrapping is based on the end time of the search. If you specify the time range of All time
, the wrapping is based on today's date. You see this in the timestamps for the _time
field and in the data series names.
Differences between SPL and SPL2
The following arguments from SPL do not have an equivalent argument in SPL2.
- series
- time_format
See also
timewrap command syntax details | timewrap command examples |
This documentation applies to the following versions of Splunk® Cloud Services: current
Feedback submitted, thanks!