<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I create a Column chart with this information? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280819#M17788</link>
    <description>&lt;P&gt;Thank you very much! I trutly appreciate it. &lt;/P&gt;</description>
    <pubDate>Mon, 06 Jun 2016 00:55:47 GMT</pubDate>
    <dc:creator>josegallo1982</dc:creator>
    <dc:date>2016-06-06T00:55:47Z</dc:date>
    <item>
      <title>How can I create a Column chart with this information?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280812#M17781</link>
      <description>&lt;P&gt;I have a search&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=metrics sourcetype=patch_report |table org, targeted, patched, patch_failed, percent_success
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;My intention is to show a column for each of these parameters and in the column the values. For example, &lt;STRONG&gt;org&lt;/STRONG&gt; contains no numeric values - it contains Organization names. The others contains numerical values.&lt;/P&gt;

&lt;P&gt;I dont know if I am using the best search by using &lt;CODE&gt;table&lt;/CODE&gt;. I am new into Splunk and trying to learn.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jun 2016 13:51:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280812#M17781</guid>
      <dc:creator>josegallo1982</dc:creator>
      <dc:date>2016-06-04T13:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: How can I create a Column chart with this information?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280813#M17782</link>
      <description>&lt;P&gt;YOu need to provide more details on the data that you have. Does it come at certain interval? How many different Org values you've? Since you've more that one data point to show per Org, you'd probably need to use Stacked column chart.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Splexicon:Stackmode"&gt;https://docs.splunk.com/Splexicon:Stackmode&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jun 2016 17:17:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280813#M17782</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-06-04T17:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: How can I create a Column chart with this information?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280814#M17783</link>
      <description>&lt;P&gt;Thank you very much Somesoni, org is the only one that has no numerical values, all of the others have percentage values, Targeted, patched, patch_failed, and percent_success have numerical values and UKN which represent Unknown, I want to have a bar chart or whatever chart that represents each of my 5 parameters (org, targeted, patched, patch_failed and percent_success) with their values represented in bars or any other chart, I don't known if table is a good function since when transforming to the Dashboard chart only "org" is showed properly, all of the others are shown as a reference line only on the right but not showing the values of them, I don't know if I explained properly, but thank you very very much in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:53:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280814#M17783</guid>
      <dc:creator>josegallo1982</dc:creator>
      <dc:date>2020-09-29T09:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: How can I create a Column chart with this information?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280815#M17784</link>
      <description>&lt;P&gt;Can you provide a few rows of these actual events?  A half-dozen of those will go &lt;EM&gt;very&lt;/EM&gt; far toward helping us help you!&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2016 01:58:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280815#M17784</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-06-05T01:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: How can I create a Column chart with this information?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280816#M17785</link>
      <description>&lt;P&gt;Hello Rich7177,&lt;/P&gt;

&lt;P&gt;Absolutely, thank you very much in advance, I will paste all the results, (they are not too much).&lt;/P&gt;

&lt;P&gt;org                                       targeted                    patched   patch_failed            percent_success&lt;BR /&gt;
Force10                               1,000                           UKN           UKN                 0%&lt;BR /&gt;
MFG Burn                          535                             UKN           UKN                 0%&lt;BR /&gt;
M&amp;amp;A PG Labs               10,000                      UKN           UKN                 0%&lt;BR /&gt;
Enterprise Solutions Labs Unknown (UKN)   UKN           UKN                 0%&lt;BR /&gt;
Network                               151                             UKN           UKN                 0%&lt;BR /&gt;
Software Group                1,230                           UKN           UKN                 0%&lt;BR /&gt;
Services Comp *               39,554                      UKN           UKN                 0%&lt;BR /&gt;
Make                                  16                              16                    0                           100%&lt;BR /&gt;
Aware                                  7                              UKN           UKN                 0%&lt;BR /&gt;
Final Overall - Non-Core    1,887                     1,726         161                         91%&lt;BR /&gt;
Domain Controllers         334                            310           24                          93%&lt;BR /&gt;
Compellent                         96                             96                    0                           100%&lt;BR /&gt;
Final Overall \x96 Core      16,995                   15,789            1,206                    93%&lt;/P&gt;

&lt;P&gt;So the parameters are: org, targeted, patched, patch_failed, and percent_success, and the values are the ones below that, I want to represend those values in Bars chart and below it the name of those parameters.&lt;/P&gt;

&lt;P&gt;As I mentioned I am using search string:&lt;BR /&gt;
index=metrics sourcetype=patch_report |table org, targeted, patched, patch_failed, percent_success&lt;/P&gt;

&lt;P&gt;But, I dont know if the "Table" is the best function of this purpose or am I missing something else, I have seen this community complex searches and I know I might be probably missing a lot of stuff in the search string, but again I apologize if this is a dumb question, but I am still in the bottom of the knowledge curve.&lt;/P&gt;

&lt;P&gt;Thank you very much in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:51:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280816#M17785</guid>
      <dc:creator>josegallo1982</dc:creator>
      <dc:date>2020-09-29T09:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: How can I create a Column chart with this information?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280817#M17786</link>
      <description>&lt;P&gt;First three results:&lt;BR /&gt;
org targeted    patched patch_failed    percent_success&lt;BR /&gt;
Force 10    1,000   UKN UKN 0%&lt;BR /&gt;
MFG Burn    535 UKN UKN 0%&lt;BR /&gt;
M&amp;amp;A PG Labs 10,000  UKN UKN 0%&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:51:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280817#M17786</guid>
      <dc:creator>josegallo1982</dc:creator>
      <dc:date>2020-09-29T09:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: How can I create a Column chart with this information?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280818#M17787</link>
      <description>&lt;P&gt;This will fake the data:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|noop|stats count as raw| eval raw="Force10 1,000 UKN UKN 0%::
   MFG Burn 535 UKN UKN 0%::
   M&amp;amp;A PG Labs 10,000 UKN UKN 0%::
   Enterprise Solutions Labs Unknown (UKN) UKN UKN 0%::
   Network 151 UKN UKN 0%::
   Software Group 1,230 UKN UKN 0%::
   Services Comp * 39,554 UKN UKN 0%::
   Make 16 16 0 100%::
   Aware 7 UKN UKN 0%::
   Final Overall - Non-Core 1,887 1,726 161 91%::
   Domain Controllers 334 310 24 93%::
   Compellent 96 96 0 100%::
   Final Overall \x96 Core 16,995 15,789 1,206 93%"
|makemv delim="::" raw | mvexpand raw | rename raw AS _raw
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then add this to do the work:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex "(?&amp;lt;org&amp;gt;.*?)\s+(?&amp;lt;targeted&amp;gt;\S+)\s+(?&amp;lt;patched&amp;gt;\S+)\s+(?&amp;lt;patch_failed&amp;gt;\S+)\s+(?&amp;lt;percent_success&amp;gt;\S+)$"
| table org targeted patched patch_failed percent_success
| foreach * [rex field=&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; mode=sed "s/[,%()]//g"]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Just click on the "Visualization" tab and select &lt;CODE&gt;Bar Chart&lt;/CODE&gt; or &lt;CODE&gt;Column Chart&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2016 19:29:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280818#M17787</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-06-05T19:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: How can I create a Column chart with this information?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280819#M17788</link>
      <description>&lt;P&gt;Thank you very much! I trutly appreciate it. &lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2016 00:55:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-can-I-create-a-Column-chart-with-this-information/m-p/280819#M17788</guid>
      <dc:creator>josegallo1982</dc:creator>
      <dc:date>2016-06-06T00:55:47Z</dc:date>
    </item>
  </channel>
</rss>

