<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need another column in chart in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-another-column-in-chart/m-p/476208#M133756</link>
    <description>&lt;P&gt;Early in the search we do a lookup&lt;/P&gt;

&lt;P&gt;lookup TimeServersV2.csv server as server OUTPUT "type" as type APP as APP&lt;/P&gt;

&lt;P&gt;type is used as part of the search succesfully, but if I add either APP or type to the untable command, it complains "The argument 'type' is invalid.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Sep 2019 19:44:50 GMT</pubDate>
    <dc:creator>tsheets13</dc:creator>
    <dc:date>2019-09-12T19:44:50Z</dc:date>
    <item>
      <title>Need another column in chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-another-column-in-chart/m-p/476206#M133754</link>
      <description>&lt;P&gt;Forgive my newbiness.  I've been working with Splunk for many years but not developing reports.  I have a report that works well.  After the search criteria and all are completed, the following shows the report...&lt;/P&gt;

&lt;P&gt;timechart span=30m max(ms) as MS, by server&lt;BR /&gt;
| eval Time=strftime(_time,"%H:%M:%S %m/%d/%Y")&lt;BR /&gt;
| untable Time, server, ms&lt;BR /&gt;
| sort +Time&lt;/P&gt;

&lt;P&gt;I got Time and server and ms columns beautifully.&lt;/P&gt;

&lt;P&gt;However, there is a field called APP that I would like to also display a column for.  How can I get the report to included this column?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 15:01:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-another-column-in-chart/m-p/476206#M133754</guid>
      <dc:creator>tsheets13</dc:creator>
      <dc:date>2019-09-12T15:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: Need another column in chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-another-column-in-chart/m-p/476207#M133755</link>
      <description>&lt;P&gt;If your events have many values for APP, then what kind of statistical function would you apply in the timechart command to render a useful value in your chart? Suppose you have 2 hosts for every 30 minutes, your table would have a rows that look like:&lt;BR /&gt;
timestamp00,host1,MS1&lt;BR /&gt;
timestamp00,host2,MS2&lt;BR /&gt;
timestamp30,host1,MS3&lt;BR /&gt;
timestamp30,host2,MS4&lt;BR /&gt;
...&lt;/P&gt;

&lt;P&gt;Is APP static value you just want tacked on the right side?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 18:26:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-another-column-in-chart/m-p/476207#M133755</guid>
      <dc:creator>jpolvino</dc:creator>
      <dc:date>2019-09-12T18:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Need another column in chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-another-column-in-chart/m-p/476208#M133756</link>
      <description>&lt;P&gt;Early in the search we do a lookup&lt;/P&gt;

&lt;P&gt;lookup TimeServersV2.csv server as server OUTPUT "type" as type APP as APP&lt;/P&gt;

&lt;P&gt;type is used as part of the search succesfully, but if I add either APP or type to the untable command, it complains "The argument 'type' is invalid.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 19:44:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-another-column-in-chart/m-p/476208#M133756</guid>
      <dc:creator>tsheets13</dc:creator>
      <dc:date>2019-09-12T19:44:50Z</dc:date>
    </item>
  </channel>
</rss>

