<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk query for Visualization in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-for-Visualization/m-p/691070#M19639</link>
    <description>&lt;P&gt;Hello Splunkers!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I want a below visualization as per attached screenshot. I have mentioned complete SPL also. Please let me know how to achieve it.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_1-1718790551185.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31373i5E45439B93E823B2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_1-1718790551185.png" alt="uagraw01_1-1718790551185.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=ABC sourcetype="stalogmessage" | fields _raw | spath output=statistical_element "StaLogMessage.StatisticalElement" | spath output=statistical_subject "StaLogMessage.StatisticalElement.StatisticalSubject" | fields - _raw | spath input=statistical_element output=statistical_item "StatisticalItem" | spath input=statistical_item output=StatisticalId "StatisticalId" | spath input=statistical_item output=Value "Value" | spath input=statistical_subject output=SubjectType "SubjectType" | mvexpand SubjectType | where SubjectType="ORDER_RECIPE" | lookup detail_lfl.csv StatisticalID as StatisticalId SubjectType as SubjectType OUTPUTNEW SymbolicName Unit | mvexpand Unit | search Unit="%" | mvexpand SymbolicName | where SymbolicName="UTILISATION"
| mvexpand Value
| mvexpand StatisticalId
| table StatisticalId Value Unit&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jun 2024 09:57:07 GMT</pubDate>
    <dc:creator>uagraw01</dc:creator>
    <dc:date>2024-06-19T09:57:07Z</dc:date>
    <item>
      <title>Splunk query for Visualization</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-for-Visualization/m-p/691070#M19639</link>
      <description>&lt;P&gt;Hello Splunkers!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I want a below visualization as per attached screenshot. I have mentioned complete SPL also. Please let me know how to achieve it.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_1-1718790551185.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31373i5E45439B93E823B2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_1-1718790551185.png" alt="uagraw01_1-1718790551185.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=ABC sourcetype="stalogmessage" | fields _raw | spath output=statistical_element "StaLogMessage.StatisticalElement" | spath output=statistical_subject "StaLogMessage.StatisticalElement.StatisticalSubject" | fields - _raw | spath input=statistical_element output=statistical_item "StatisticalItem" | spath input=statistical_item output=StatisticalId "StatisticalId" | spath input=statistical_item output=Value "Value" | spath input=statistical_subject output=SubjectType "SubjectType" | mvexpand SubjectType | where SubjectType="ORDER_RECIPE" | lookup detail_lfl.csv StatisticalID as StatisticalId SubjectType as SubjectType OUTPUTNEW SymbolicName Unit | mvexpand Unit | search Unit="%" | mvexpand SymbolicName | where SymbolicName="UTILISATION"
| mvexpand Value
| mvexpand StatisticalId
| table StatisticalId Value Unit&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2024 09:57:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-for-Visualization/m-p/691070#M19639</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-06-19T09:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query for Visualization</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-for-Visualization/m-p/691079#M19641</link>
      <description>&lt;P&gt;HI &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try this: Data display &amp;gt; Data value display: All.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dataisbeautiful_0-1718794172946.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31376i5F812D93120A1077/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dataisbeautiful_0-1718794172946.png" alt="dataisbeautiful_0-1718794172946.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2024 10:50:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-for-Visualization/m-p/691079#M19641</guid>
      <dc:creator>dataisbeautiful</dc:creator>
      <dc:date>2024-06-19T10:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query for Visualization</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-for-Visualization/m-p/691134#M19649</link>
      <description>&lt;P&gt;What is the x-axis you need.&lt;/P&gt;&lt;P&gt;You have 3 fields output in your search&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;| table StatisticalId Value Unit&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;and there is a lot of mvexpand logic going on... and that seems like you are going to multiple your data significantly as there's no correlation between each of the MV values you are expanding.&lt;/P&gt;&lt;P&gt;That aside, the basic command to create the chart would be something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| chart max(Value) over Unit by StatisticalId&lt;/LI-CODE&gt;&lt;P&gt;which would put Unit on the x-axis. Swap Unit and StatisticalId to make&amp;nbsp;StatisticalId the x-axis&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2024 22:42:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-for-Visualization/m-p/691134#M19649</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-06-19T22:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query for Visualization</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-for-Visualization/m-p/691238#M19660</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=ABC sourcetype="stalogmessage" 
| fields _raw 
| spath output=statistical_element "StaLogMessage.StatisticalElement" 
| spath output=statistical_subject "StaLogMessage.StatisticalElement.StatisticalSubject" 
| fields - _raw
| mvexpand statistical_element  
| mvexpand statistical_subject
| spath input=statistical_element output=statistical_item "StatisticalItem"
| spath input=statistical_item output=StatisticalId "StatisticalId"
| spath input=statistical_item output=Value "Value"
| spath input=statistical_subject output=SubjectType "SubjectType"
| where SubjectType="ORDER_RECIPE"
| stats count by StatisticalId Value SubjectType _time
| lookup detail_lfl.csv StatisticalID as StatisticalId SubjectType as SubjectType OUTPUTNEW SymbolicName
| mvexpand SymbolicName
| where SymbolicName="UTILISATION" 
|  strcat "raw" "," SymbolicName group_name
| stats min(Value) AS min_value, max(Value) AS max_value, sum(Value) AS sum_value, count AS count BY SymbolicName group_name StatisticalId _time
| eval min_value=coalesce(min_value,value), max_value=coalesce(max_value,value), sum_value=coalesce(sum_value,value), count=coalesce(count,1) 
| fields StatisticalId min_value max_value sum_value count group_name _time
| dedup StatisticalId _time group_name
| fields - _virtual_ _cd_ 
| fillnull value="" 
| timechart span=1h minspan=3600s eval(round(min(min_value),2)) AS "Minimum", eval(round(max(max_value),2)) AS "Maximum", eval(round(sum(sum_value),2)) AS summed, eval(round(sum(count),2)) AS counted 
| eval "Average" = round(summed/counted, 2) 
| fields - summed counted&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I am using above query to visualize the graph in Maximum , minimum and average. But my values are looking different.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1718949107434.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31397i7D91782D23320D81/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1718949107434.png" alt="uagraw01_0-1718949107434.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Expected result I want :&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_2-1718949246939.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31399i26337C900200C286/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_2-1718949246939.png" alt="uagraw01_2-1718949246939.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;Please help me what I need to fix in the query to achieve expected results.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 05:56:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-for-Visualization/m-p/691238#M19660</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-06-21T05:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query for Visualization</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-for-Visualization/m-p/691253#M19661</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp; In x-axis I am having time.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 07:55:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-for-Visualization/m-p/691253#M19661</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-06-21T07:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query for Visualization</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-for-Visualization/m-p/691259#M19662</link>
      <description>&lt;P&gt;At the very basic level you are producing a timechart with a span=1h and you want a time chart with a daily set of numbers, so that's wrong.&lt;/P&gt;&lt;P&gt;However, it's impossible to say what is going on here, you have so much going on in the search.&lt;/P&gt;&lt;P&gt;You have to go back to basics, which means start with the basic data and at EACH step of your SPL make sure the data is giving you what you expect.&lt;/P&gt;&lt;P&gt;So, take a very small sample set of data and run the SPL line by line, check the output after each line. When you are happy that the data is giving you the correct output from 1 line of SPL, add in the next line.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 08:14:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-for-Visualization/m-p/691259#M19662</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-06-21T08:14:25Z</dc:date>
    </item>
  </channel>
</rss>

