<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Chart Multiple (4) Fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369014#M108757</link>
    <description>&lt;P&gt;ok, please check this... as &lt;CODE&gt;timechart by Status&lt;/CODE&gt; can be one idea.. please check the image. &lt;BR /&gt;
&lt;PRE&gt;sourcetype="csvtest" | timechart span=1m sum(No) by Status | fillnull value=0&lt;/PRE&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3115iABCEE5439DE8233C/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jun 2017 05:26:25 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2017-06-23T05:26:25Z</dc:date>
    <item>
      <title>Chart Multiple (4) Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369011#M108754</link>
      <description>&lt;P&gt;Is it possible to create a chart out of 4 fields in Splunk?&lt;BR /&gt;
I am trying to create a chart shown below but I was only able to using 3 fields (without the status). My given data have 4 fields. Any suggestions to this? Thanks in advance.&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3116i45AED30B650089A2/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 04:18:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369011#M108754</guid>
      <dc:creator>arielpconsolaci</dc:creator>
      <dc:date>2017-06-23T04:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: Chart Multiple (4) Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369012#M108755</link>
      <description>&lt;P&gt;may we know your current splunk search query..&lt;BR /&gt;
you can do some split by or layered/multi-stack options I think. &lt;BR /&gt;
one question - how status can be embedded on this chart - is a tricky issue. &lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 04:30:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369012#M108755</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-06-23T04:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: Chart Multiple (4) Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369013#M108756</link>
      <description>&lt;P&gt;Thank you for your response @inventsekar.&lt;/P&gt;

&lt;P&gt;My query is as simple as below. &lt;/P&gt;

&lt;P&gt;index=component_server&lt;BR /&gt;
| timechart span=1m sum(No.) by Component&lt;BR /&gt;
| fillnull value=0&lt;/P&gt;

&lt;P&gt;Yes. I am having troubles incorporating the 'Status'. Can you advise on this?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 04:37:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369013#M108756</guid>
      <dc:creator>arielpconsolaci</dc:creator>
      <dc:date>2017-06-23T04:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Chart Multiple (4) Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369014#M108757</link>
      <description>&lt;P&gt;ok, please check this... as &lt;CODE&gt;timechart by Status&lt;/CODE&gt; can be one idea.. please check the image. &lt;BR /&gt;
&lt;PRE&gt;sourcetype="csvtest" | timechart span=1m sum(No) by Status | fillnull value=0&lt;/PRE&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3115iABCEE5439DE8233C/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 05:26:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369014#M108757</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-06-23T05:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: Chart Multiple (4) Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369015#M108758</link>
      <description>&lt;P&gt;Thank you for this, @inventsekar. However, i'd need a chart (based on component and status) close to the screenshot i've sent above.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 07:08:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369015#M108758</guid>
      <dc:creator>arielpconsolaci</dc:creator>
      <dc:date>2017-06-23T07:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Chart Multiple (4) Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369016#M108759</link>
      <description>&lt;P&gt;What about something like:&lt;/P&gt;

&lt;P&gt;index=component_server&lt;BR /&gt;
| timechart span=1m sum(No.), values(status) AS status by component&lt;BR /&gt;
| fillnull value=0&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 07:18:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369016#M108759</guid>
      <dc:creator>HeinzWaescher</dc:creator>
      <dc:date>2017-06-23T07:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: Chart Multiple (4) Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369017#M108760</link>
      <description>&lt;P&gt;Thank you for this suggestion @HeinzWaescher. This however does not show the 'Status'.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 09:26:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369017#M108760</guid>
      <dc:creator>arielpconsolaci</dc:creator>
      <dc:date>2017-06-23T09:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: Chart Multiple (4) Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369018#M108761</link>
      <description>&lt;P&gt;what version of splunk are you currently running? if you are on 6.6, i would recommend the new Trellis feature for this. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults |eval data="_time=1498217650,component=A,status=running,no=10 _time=1498217651,component=A,status=running,no=20 _time=1498217652,component=A,status=offline,no=10 _time=1498217653,component=A,status=online,no=30 _time=1498217650,component=B,status=running,no=20 _time=1498217651,component=B,status=offline,no=40 _time=1498217652,component=B,status=offline,no=10 _time=1498217653,component=B,status=running,no=40"|makemv data |mvexpand data|eval _raw=data|kv|eval _time=time|stats values(no) as no by _time component status|eval{status}=no|fields - status - no
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;you can split each component into its own chart with the same query. Splunk does not currently have a way, that I know of, to allow for multi-level x-axis, like Excel does, and the trellis feature is a close second.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 11:49:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Chart-Multiple-4-Fields/m-p/369018#M108761</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-06-23T11:49:10Z</dc:date>
    </item>
  </channel>
</rss>

