<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Visualization is not giving below results in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Visualization-is-not-giving-below-results/m-p/684506#M56035</link>
    <description>&lt;P&gt;Hello Splunkers!!&lt;/P&gt;
&lt;P&gt;I want to achieve below screenshot visualization.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1713357668754.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30446iEF7F7B5D21C20B39/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1713357668754.png" alt="uagraw01_0-1713357668754.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below is my current query :&lt;/P&gt;
&lt;P&gt;======================================================&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=ABC
sourcetype=ReplenishmentOrderAssign OR sourcetype=ReplenishmentOrderCompleted OR sourcetype=ReplenishmentOrderStarted OR sourcetype=ReplenishmentOrderCancel
| rex field=_raw "SenderFmInstanceName\&amp;gt;(?P&amp;lt;Workstation&amp;gt;[A-Za-z0-9]+\/[A-Za-z0-9]+)\&amp;lt;\/SenderFmInstanceName"
| rename ReplenishmentOrderAssign.OrderId as OrderId
| eval TimeAssigned=if(like(sourcetype,"%Assign"),_time,null) , TimeStarted=if(like(sourcetype,"%Started"),_time,null), TimeCompleted=if(like(sourcetype,"%Completed"),_time,null)
| eventstats count(OrderId) as CountOrderTypes by OrderId
| timechart span=5m count(TimeAssigned) as Assigned count(TimeStarted) as Started count(TimeCompleted) as Completed by Workstation
| streamstats sum(*)
| foreach "sum(Assigned:*)"
[| eval &amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;Assigned='&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'-'sum(Completed:&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;)']
| foreach "sum(Started:*)"
[| eval &amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;Started='&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'-'sum(Completed:&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;)']
| fields _time DEP*
| foreach "DEP/*"
[| eval &amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;=if('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'&amp;gt;0,1,0)]
| fields - DEP/*
| foreach "*Assigned"
[| eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;='&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'-'&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;Started']
| foreach "*Assigned"
[| eval &amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;Idle=1-'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'-'&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;Started']
| addtotals *Started fieldname=Active
| addtotals *Assigned fieldname=Assigned
| addtotals *Idle fieldname=Idle
| fields _time Idle Assigned Active
| bin span=$span$ _time
| eventstats sum(*) as * by _time
| dedup _time&lt;/LI-CODE&gt;
&lt;P&gt;Current query is giving me below visualization. Please help me where I need to change in the query to get the above visualization?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1713357527227.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30445i61DF8AE3A1DC1ABD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1713357527227.png" alt="uagraw01_0-1713357527227.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Apr 2024 15:40:24 GMT</pubDate>
    <dc:creator>uagraw01</dc:creator>
    <dc:date>2024-04-17T15:40:24Z</dc:date>
    <item>
      <title>Splunk Visualization is not giving below results</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Visualization-is-not-giving-below-results/m-p/684506#M56035</link>
      <description>&lt;P&gt;Hello Splunkers!!&lt;/P&gt;
&lt;P&gt;I want to achieve below screenshot visualization.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1713357668754.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30446iEF7F7B5D21C20B39/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1713357668754.png" alt="uagraw01_0-1713357668754.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below is my current query :&lt;/P&gt;
&lt;P&gt;======================================================&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=ABC
sourcetype=ReplenishmentOrderAssign OR sourcetype=ReplenishmentOrderCompleted OR sourcetype=ReplenishmentOrderStarted OR sourcetype=ReplenishmentOrderCancel
| rex field=_raw "SenderFmInstanceName\&amp;gt;(?P&amp;lt;Workstation&amp;gt;[A-Za-z0-9]+\/[A-Za-z0-9]+)\&amp;lt;\/SenderFmInstanceName"
| rename ReplenishmentOrderAssign.OrderId as OrderId
| eval TimeAssigned=if(like(sourcetype,"%Assign"),_time,null) , TimeStarted=if(like(sourcetype,"%Started"),_time,null), TimeCompleted=if(like(sourcetype,"%Completed"),_time,null)
| eventstats count(OrderId) as CountOrderTypes by OrderId
| timechart span=5m count(TimeAssigned) as Assigned count(TimeStarted) as Started count(TimeCompleted) as Completed by Workstation
| streamstats sum(*)
| foreach "sum(Assigned:*)"
[| eval &amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;Assigned='&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'-'sum(Completed:&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;)']
| foreach "sum(Started:*)"
[| eval &amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;Started='&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'-'sum(Completed:&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;)']
| fields _time DEP*
| foreach "DEP/*"
[| eval &amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;=if('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'&amp;gt;0,1,0)]
| fields - DEP/*
| foreach "*Assigned"
[| eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;='&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'-'&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;Started']
| foreach "*Assigned"
[| eval &amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;Idle=1-'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'-'&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;Started']
| addtotals *Started fieldname=Active
| addtotals *Assigned fieldname=Assigned
| addtotals *Idle fieldname=Idle
| fields _time Idle Assigned Active
| bin span=$span$ _time
| eventstats sum(*) as * by _time
| dedup _time&lt;/LI-CODE&gt;
&lt;P&gt;Current query is giving me below visualization. Please help me where I need to change in the query to get the above visualization?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1713357527227.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30445i61DF8AE3A1DC1ABD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1713357527227.png" alt="uagraw01_0-1713357527227.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 15:40:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Visualization-is-not-giving-below-results/m-p/684506#M56035</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-04-17T15:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Visualization is not giving below results</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Visualization-is-not-giving-below-results/m-p/684543#M56038</link>
      <description>&lt;P&gt;Is there anybody who can help me here ?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 17:43:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Visualization-is-not-giving-below-results/m-p/684543#M56038</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-04-17T17:43:27Z</dc:date>
    </item>
  </channel>
</rss>

