<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I create a bar chart with positive and negative values? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377952#M110826</link>
    <description>&lt;P&gt;Thanks for the update. I should have added more notes to my query. Log from machine A &lt;CODE&gt;index="machine_a" category=web event_count=100&lt;/CODE&gt; and log from machine B &lt;CODE&gt;index="machine_a" category=web event_count=80&lt;/CODE&gt;. The desired output would be 20 as machine A has 20 more events than machine B. If machine B &lt;CODE&gt;event_count&lt;/CODE&gt; is 100 and machine A &lt;CODE&gt;event_count&lt;/CODE&gt; is 80, -20 would be the desired output. While reading your query, I think it takes the difference in the number of LOGS and not &lt;CODE&gt;event_count&lt;/CODE&gt;. I am also confused as to how to reference &lt;CODE&gt;machineA&lt;/CODE&gt; and &lt;CODE&gt;machineB&lt;/CODE&gt; values as you did above&lt;/P&gt;</description>
    <pubDate>Tue, 01 May 2018 20:11:31 GMT</pubDate>
    <dc:creator>liondancer</dc:creator>
    <dc:date>2018-05-01T20:11:31Z</dc:date>
    <item>
      <title>How can I create a bar chart with positive and negative values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377947#M110821</link>
      <description>&lt;P&gt;How can I create a bar chart with positive and negative values? Here is the use case I have.&lt;/P&gt;

&lt;P&gt;I have events coming in per hour from two different machines, A and B. If machine A has 10 more events generate than machine B, the bar chart should shoot UP 10 units. If machine B has 15 more events than machine A, then the bar chart should shoot DOWN 15 units. If machine A and machine B have the same number of events generated then there would be no units displayed. &lt;/P&gt;

&lt;P&gt;I am pretty new to Splunk so I am not sure where to start to create something like this&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 19:24:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377947#M110821</guid>
      <dc:creator>liondancer</dc:creator>
      <dc:date>2018-04-30T19:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: How can I create a bar chart with positive and negative values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377948#M110822</link>
      <description>&lt;P&gt;Try something on this line.. (assuming you want some sort of timechart of difference of counts in both machines. Also assuming there is a field machine in your logs with value machineA and machineB)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base search which collects required logs from machineA and machineB
| timechart span=1d count by machine
| rename COMMENT as "Above line would generate a column for values of field machine, so if the field machine has value machineA and machineB, you'd see two fields called machineA and machineB."
| eval Difference='machineA'-'machineB'
| table _time Difference
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 30 Apr 2018 21:19:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377948#M110822</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-04-30T21:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: How can I create a bar chart with positive and negative values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377949#M110823</link>
      <description>&lt;P&gt;Like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index="machine_a" OR index="machine_b") category=web
| timechart span=YourSpanHere count BY index
| eval delta = machine_a - machine_b
| timechart span=YourSpanHere first(delta) AS delta
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;BTW, putting each host in a separate index is probably not the right way to partition your data (although in some cases it can make sense).&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 16:31:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377949#M110823</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-05-01T16:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: How can I create a bar chart with positive and negative values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377950#M110824</link>
      <description>&lt;P&gt;Being new to Splunk, how can I PIPE the logs from machine A and machine B to the same chart? My query looks something like this for machine A &lt;CODE&gt;index="machine_a" category=web&lt;/CODE&gt; and this for machine B &lt;CODE&gt;index="machine_b" category=web&lt;/CODE&gt;. &lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 19:24:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377950#M110824</guid>
      <dc:creator>liondancer</dc:creator>
      <dc:date>2018-05-01T19:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: How can I create a bar chart with positive and negative values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377951#M110825</link>
      <description>&lt;P&gt;See my answer.&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 19:43:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377951#M110825</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-05-01T19:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: How can I create a bar chart with positive and negative values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377952#M110826</link>
      <description>&lt;P&gt;Thanks for the update. I should have added more notes to my query. Log from machine A &lt;CODE&gt;index="machine_a" category=web event_count=100&lt;/CODE&gt; and log from machine B &lt;CODE&gt;index="machine_a" category=web event_count=80&lt;/CODE&gt;. The desired output would be 20 as machine A has 20 more events than machine B. If machine B &lt;CODE&gt;event_count&lt;/CODE&gt; is 100 and machine A &lt;CODE&gt;event_count&lt;/CODE&gt; is 80, -20 would be the desired output. While reading your query, I think it takes the difference in the number of LOGS and not &lt;CODE&gt;event_count&lt;/CODE&gt;. I am also confused as to how to reference &lt;CODE&gt;machineA&lt;/CODE&gt; and &lt;CODE&gt;machineB&lt;/CODE&gt; values as you did above&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 20:11:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377952#M110826</guid>
      <dc:creator>liondancer</dc:creator>
      <dc:date>2018-05-01T20:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: How can I create a bar chart with positive and negative values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377953#M110827</link>
      <description>&lt;P&gt;Given your clarification in my previous answer, try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; (index="machine_a" OR index="machine_b") category=web
 | timechart span=YourSpanHere avg(event_count) BY index
 | eval delta = machine_a - machine_b
 | timechart span=YourSpanHere first(delta) AS delta
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You can replace &lt;CODE&gt;avg&lt;/CODE&gt; with &lt;CODE&gt;max&lt;/CODE&gt; or &lt;CODE&gt;latest&lt;/CODE&gt; or some other aggregation more appropriate.&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 20:32:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377953#M110827</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-05-01T20:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: How can I create a bar chart with positive and negative values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377954#M110828</link>
      <description>&lt;P&gt;I had a typo (now corrected) where &lt;CODE&gt;machineA&lt;/CODE&gt; should have been &lt;CODE&gt;machine_a&lt;/CODE&gt;, etc.  See my new answer for better solution.&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 20:34:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-create-a-bar-chart-with-positive-and-negative-values/m-p/377954#M110828</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-05-01T20:34:06Z</dc:date>
    </item>
  </channel>
</rss>

