<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to use sparkline in search with inputlookup? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429054#M28270</link>
    <description>&lt;P&gt;Could you plz try the following:&lt;/P&gt;

&lt;P&gt;| inputlookup  lookupfile.csv &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Is there any output? &lt;/LI&gt;
&lt;LI&gt;Is there a field with values?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;If yes, try:&lt;BR /&gt;
| inputlookup lookupfile.csv | chart sparkline count by field_you_are_looking_for&lt;/P&gt;

&lt;P&gt;Greetings, Chris&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 01:38:56 GMT</pubDate>
    <dc:creator>chris1337</dc:creator>
    <dc:date>2020-09-30T01:38:56Z</dc:date>
    <item>
      <title>How to use sparkline in search with inputlookup?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429051#M28267</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I try used it...  &lt;CODE&gt;index=indexname | chart sparkline count by field&lt;/CODE&gt; and this worked, but this not worked  &lt;CODE&gt;| inputlookup lookupname | chart sparkline count by field&lt;/CODE&gt; why and how to fix it? How to I must use sparkline with inputlookup?&lt;BR /&gt;
Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 13:32:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429051#M28267</guid>
      <dc:creator>sbimizry</dc:creator>
      <dc:date>2019-08-06T13:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to use sparkline in search with inputlookup?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429052#M28268</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;are you sure, that your inputlookup is delivering some fields+values? Do you use the right fieldname to count? Is this fieldname available in your lookup output?&lt;/P&gt;

&lt;P&gt;I tested it, there are no problems right now.&lt;/P&gt;

&lt;P&gt;Greetings Chris&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 13:55:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429052#M28268</guid>
      <dc:creator>chris1337</dc:creator>
      <dc:date>2019-08-06T13:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to use sparkline in search with inputlookup?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429053#M28269</link>
      <description>&lt;P&gt;Yes, I'm sure everything is correct, but they do not work&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 14:05:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429053#M28269</guid>
      <dc:creator>sbimizry</dc:creator>
      <dc:date>2019-08-06T14:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to use sparkline in search with inputlookup?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429054#M28270</link>
      <description>&lt;P&gt;Could you plz try the following:&lt;/P&gt;

&lt;P&gt;| inputlookup  lookupfile.csv &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Is there any output? &lt;/LI&gt;
&lt;LI&gt;Is there a field with values?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;If yes, try:&lt;BR /&gt;
| inputlookup lookupfile.csv | chart sparkline count by field_you_are_looking_for&lt;/P&gt;

&lt;P&gt;Greetings, Chris&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:38:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429054#M28270</guid>
      <dc:creator>chris1337</dc:creator>
      <dc:date>2020-09-30T01:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to use sparkline in search with inputlookup?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429055#M28271</link>
      <description>&lt;P&gt;Output from lookup is exist and fields too, but sparkline not work&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 14:48:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429055#M28271</guid>
      <dc:creator>sbimizry</dc:creator>
      <dc:date>2019-08-06T14:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to use sparkline in search with inputlookup?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429056#M28272</link>
      <description>&lt;P&gt;Ok, then I don´t know. My local test here worked fine. I´m sorry, I could not help you.&lt;/P&gt;

&lt;P&gt;Greetings Chris&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 14:50:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429056#M28272</guid>
      <dc:creator>chris1337</dc:creator>
      <dc:date>2019-08-06T14:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to use sparkline in search with inputlookup?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429057#M28273</link>
      <description>&lt;P&gt;A sparkline  is a trend over time. Does your inputlookup include _time? &lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 14:51:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429057#M28273</guid>
      <dc:creator>kmaron</dc:creator>
      <dc:date>2019-08-06T14:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to use sparkline in search with inputlookup?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429058#M28274</link>
      <description>&lt;P&gt;Yes, this field exists&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 15:16:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429058#M28274</guid>
      <dc:creator>sbimizry</dc:creator>
      <dc:date>2019-08-06T15:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to use sparkline in search with inputlookup?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429059#M28275</link>
      <description>&lt;P&gt;@sbimizry what is the field containing epoch time in your lookup? Or do you have time in lookup available as String time? In either case community would be able to assist you better if you provide field names with some sample data from your lookup file.&lt;/P&gt;

&lt;P&gt;For example &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;time          field
2019/01/01 20:08:00          value1
2019/01/01 20:09:00          value1
2019/01/01 20:10:00          value1
2019/01/01 20:08:00          value2
2019/01/01 20:10:00          value2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then following would be the query. If time in lookup is String time following eval with &lt;CODE&gt;strptime()&lt;/CODE&gt; would be required to convert string time to epoch. Otherwise _time can be directly overridden with &lt;CODE&gt;| eval _time=time&lt;/CODE&gt; when time field is already epoch time.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| inputlookup lookupname 
| eval _time=strptime(time,"%Y/%m/%d %H:%M:%S")
| chart sparkline count by field
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 06 Aug 2019 16:26:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429059#M28275</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2019-08-06T16:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to use sparkline in search with inputlookup?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429060#M28276</link>
      <description>&lt;P&gt;I did it, but it doesn’t work.&lt;BR /&gt;
Example my data:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;PRE&gt;&lt;CODE&gt;result_time                 name
1565083380               value1
1565083230               value1
1565087350               value2
1565078330               value3
1565066540               value2
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Wed, 07 Aug 2019 10:00:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/429060#M28276</guid>
      <dc:creator>sbimizry</dc:creator>
      <dc:date>2019-08-07T10:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to use sparkline in search with inputlookup?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/610878#M50079</link>
      <description>&lt;P&gt;If anyone ever runs into this in the future and are having issues like I was, everything in this post applies but even though you are calling | inputlookup and your searching time frame doesn't apply to bringing back results, you do need to search over the range for the sparkline to form properly.&amp;nbsp; Basically for a 30 days sparkline, making sure you run the search over the last 30 days even though its not actually searching 30 days of events.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 21:46:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-use-sparkline-in-search-with-inputlookup/m-p/610878#M50079</guid>
      <dc:creator>efloss</dc:creator>
      <dc:date>2022-08-25T21:46:08Z</dc:date>
    </item>
  </channel>
</rss>

