<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic xyseries, reporting on multiple data series confusion in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/xyseries-reporting-on-multiple-data-series-confusion/m-p/63076#M3291</link>
    <description>&lt;P&gt;I have log entries that contain, among other things, fields called AcctID and exec_time. I have a user who wants to do, essentially:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=statslog | timechart count, avg(exec_time) by AcctID
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Since I know this to not be directly possible in 4.1, I went to the strategy laid out in &lt;A href="http://www.splunk.com/base/Documentation/4.1.6/User/ReportOfMultipleDataSeries" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.6/User/ReportOfMultipleDataSeries&lt;/A&gt;. My search ends up being:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=*prod* sourcetype=statslog "exec=getSingleAvailability" exec_time &amp;gt; 0 
| stats count as cnt, avg(exec_time) as avgexec by AcctID 
| eval s1="count avgexec" 
| makemv s1 | mvexpand s1 
| eval yval=case(s1=="count",cnt,s1=="avgexec",avgexec) | eval series=AcctID+":"+s1 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And I get results as expected, like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;     AcctID cnt  avgexec     s1        series        yval 
1   7490728 23  391.826087  count   7490728:count   23
2   7490728 23  391.826087  avgexec 7490728:avgexec 391.826087
3   5459551 22  193.954545  count   5459551:count   22
4   5459551 22  193.954545  avgexec 5459551:avgexec 193.954545
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But when I add the final &lt;CODE&gt;| xyseries _time,series,yval&lt;/CODE&gt; to the search, I get "No results found"&lt;/P&gt;

&lt;P&gt;What am I missing?&lt;/P&gt;</description>
    <pubDate>Sat, 19 Mar 2011 00:27:44 GMT</pubDate>
    <dc:creator>pde23</dc:creator>
    <dc:date>2011-03-19T00:27:44Z</dc:date>
    <item>
      <title>xyseries, reporting on multiple data series confusion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/xyseries-reporting-on-multiple-data-series-confusion/m-p/63076#M3291</link>
      <description>&lt;P&gt;I have log entries that contain, among other things, fields called AcctID and exec_time. I have a user who wants to do, essentially:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=statslog | timechart count, avg(exec_time) by AcctID
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Since I know this to not be directly possible in 4.1, I went to the strategy laid out in &lt;A href="http://www.splunk.com/base/Documentation/4.1.6/User/ReportOfMultipleDataSeries" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.6/User/ReportOfMultipleDataSeries&lt;/A&gt;. My search ends up being:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=*prod* sourcetype=statslog "exec=getSingleAvailability" exec_time &amp;gt; 0 
| stats count as cnt, avg(exec_time) as avgexec by AcctID 
| eval s1="count avgexec" 
| makemv s1 | mvexpand s1 
| eval yval=case(s1=="count",cnt,s1=="avgexec",avgexec) | eval series=AcctID+":"+s1 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And I get results as expected, like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;     AcctID cnt  avgexec     s1        series        yval 
1   7490728 23  391.826087  count   7490728:count   23
2   7490728 23  391.826087  avgexec 7490728:avgexec 391.826087
3   5459551 22  193.954545  count   5459551:count   22
4   5459551 22  193.954545  avgexec 5459551:avgexec 193.954545
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But when I add the final &lt;CODE&gt;| xyseries _time,series,yval&lt;/CODE&gt; to the search, I get "No results found"&lt;/P&gt;

&lt;P&gt;What am I missing?&lt;/P&gt;</description>
      <pubDate>Sat, 19 Mar 2011 00:27:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/xyseries-reporting-on-multiple-data-series-confusion/m-p/63076#M3291</guid>
      <dc:creator>pde23</dc:creator>
      <dc:date>2011-03-19T00:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: xyseries, reporting on multiple data series confusion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/xyseries-reporting-on-multiple-data-series-confusion/m-p/63077#M3292</link>
      <description>&lt;P&gt;I just walked through the docs myself using some access data use cases and it looks to me like there are mistakes in the documentation. &lt;/P&gt;

&lt;P&gt;The docs give this example: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=application_servers 
| stats sum(handledRequests) as hRs, avg(sessions) as ssns by source 
| eval s1="handledReqs sessions" 
| makemv s1 | mvexpand s1 
| eval yval=case(s1=="handledReqs",hRs,s1=="sessions",ssns) 
| eval series=host+":"+s1 
| xyseries _time,series,yval
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The main mistake is that the stats should be &lt;CODE&gt;by source, _time&lt;/CODE&gt; not just &lt;CODE&gt;by source&lt;/CODE&gt;.   Without a _time field coming out of the &lt;CODE&gt;stats&lt;/CODE&gt; clause, the xyseries would indeed yield no results because there wouldnt be any _time fields at that point. &lt;/P&gt;

&lt;P&gt;There's also a second mistake although it's minor and it doesnt seem to have tripped you up at all  -- the &lt;CODE&gt;eval series=host+":"+s1&lt;/CODE&gt;  should be &lt;CODE&gt;eval series=source+":"+s1&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I think you were following the docs perfectly, but the docs themselves got garbled at some point.  It happens. &lt;/P&gt;

&lt;P&gt;So try this: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=*prod* sourcetype=statslog "exec=getSingleAvailability" exec_time &amp;gt; 0 
| stats count as cnt, avg(exec_time) as avgexec by AcctID, _time
| eval s1="count avgexec" 
| makemv s1 | mvexpand s1 
| eval yval=case(s1=="count",cnt,s1=="avgexec",avgexec) 
| eval series=AcctID+":"+s1 
| xyseries _time, series, yval
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 19 Mar 2011 14:10:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/xyseries-reporting-on-multiple-data-series-confusion/m-p/63077#M3292</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2011-03-19T14:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: xyseries, reporting on multiple data series confusion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/xyseries-reporting-on-multiple-data-series-confusion/m-p/63078#M3293</link>
      <description>&lt;P&gt;docs are fixed.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2011 00:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/xyseries-reporting-on-multiple-data-series-confusion/m-p/63078#M3293</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-03-21T00:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: xyseries, reporting on multiple data series confusion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/xyseries-reporting-on-multiple-data-series-confusion/m-p/63079#M3294</link>
      <description>&lt;P&gt;gerald's the best. &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2011 12:04:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/xyseries-reporting-on-multiple-data-series-confusion/m-p/63079#M3294</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2011-03-21T12:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: xyseries, reporting on multiple data series confusion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/xyseries-reporting-on-multiple-data-series-confusion/m-p/63080#M3295</link>
      <description>&lt;P&gt;That's the ticket. Thanks, Doctor Nick!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2011 00:08:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/xyseries-reporting-on-multiple-data-series-confusion/m-p/63080#M3295</guid>
      <dc:creator>pde23</dc:creator>
      <dc:date>2011-03-22T00:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: xyseries, reporting on multiple data series confusion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/xyseries-reporting-on-multiple-data-series-confusion/m-p/63081#M3296</link>
      <description>&lt;P&gt;Shouldn't the _time be binned before that first stats command?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 20:55:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/xyseries-reporting-on-multiple-data-series-confusion/m-p/63081#M3296</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-02-10T20:55:38Z</dc:date>
    </item>
  </channel>
</rss>

