<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using timechat with 2 fields without any field calculation in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Using-timechat-with-2-fields-without-any-field-calculation/m-p/252968#M175848</link>
    <description>&lt;P&gt;Hi, &lt;BR /&gt;
I'm new in Splunk (and my knowledge is very very basic) and I have to build a complex dashboard with multiple indexes. I've tried googling it and I did not find anything related to my needs.&lt;BR /&gt;
So, I have my index with a log file from a group of servers (farm) and that log is imported every hour. This log has 2 sourcetypes (users and computers).&lt;/P&gt;

&lt;P&gt;My logfile has this name: ControlUp_Sessions_01_24_2017_12_00.csv and "12_00" represents the hour that is imported to splunk.&lt;/P&gt;

&lt;P&gt;I need to build a line chart by hour for a specific user (variable from an input field) with his "session Latency" and "CPU Usage"&lt;/P&gt;

&lt;P&gt;With this query I have my results:&lt;BR /&gt;
index=controlup sourcetype="csv-sessions" User="XPTO"&lt;BR /&gt;
| table "Protocol Latency _ Session Avg", CPU&lt;/P&gt;

&lt;P&gt;But using  a "Timechart" with "span=1h" all examples have an "eval" or an "avg" and I don't need that.&lt;/P&gt;

&lt;P&gt;I've tried and I have the results but only with AVG:&lt;BR /&gt;
index=controlup  sourcetype="csv-sessions" User="XPTO" &lt;BR /&gt;
| timechart span=60m avg("Protocol Latency _ Session Avg")&lt;BR /&gt;
| appendcols [search index=controlup sourcetype="csv-sessions" User="XPTO" | timechart span=60m avg(CPU)]&lt;/P&gt;

&lt;P&gt;Basiclly I need a timeline with CPU usage and latency during the day for a selected user without any calculated value/field.&lt;BR /&gt;
Can someone point me to the rigth direction, please?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 12:32:49 GMT</pubDate>
    <dc:creator>fariapm1</dc:creator>
    <dc:date>2020-09-29T12:32:49Z</dc:date>
    <item>
      <title>Using timechat with 2 fields without any field calculation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-timechat-with-2-fields-without-any-field-calculation/m-p/252968#M175848</link>
      <description>&lt;P&gt;Hi, &lt;BR /&gt;
I'm new in Splunk (and my knowledge is very very basic) and I have to build a complex dashboard with multiple indexes. I've tried googling it and I did not find anything related to my needs.&lt;BR /&gt;
So, I have my index with a log file from a group of servers (farm) and that log is imported every hour. This log has 2 sourcetypes (users and computers).&lt;/P&gt;

&lt;P&gt;My logfile has this name: ControlUp_Sessions_01_24_2017_12_00.csv and "12_00" represents the hour that is imported to splunk.&lt;/P&gt;

&lt;P&gt;I need to build a line chart by hour for a specific user (variable from an input field) with his "session Latency" and "CPU Usage"&lt;/P&gt;

&lt;P&gt;With this query I have my results:&lt;BR /&gt;
index=controlup sourcetype="csv-sessions" User="XPTO"&lt;BR /&gt;
| table "Protocol Latency _ Session Avg", CPU&lt;/P&gt;

&lt;P&gt;But using  a "Timechart" with "span=1h" all examples have an "eval" or an "avg" and I don't need that.&lt;/P&gt;

&lt;P&gt;I've tried and I have the results but only with AVG:&lt;BR /&gt;
index=controlup  sourcetype="csv-sessions" User="XPTO" &lt;BR /&gt;
| timechart span=60m avg("Protocol Latency _ Session Avg")&lt;BR /&gt;
| appendcols [search index=controlup sourcetype="csv-sessions" User="XPTO" | timechart span=60m avg(CPU)]&lt;/P&gt;

&lt;P&gt;Basiclly I need a timeline with CPU usage and latency during the day for a selected user without any calculated value/field.&lt;BR /&gt;
Can someone point me to the rigth direction, please?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:32:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-timechat-with-2-fields-without-any-field-calculation/m-p/252968#M175848</guid>
      <dc:creator>fariapm1</dc:creator>
      <dc:date>2020-09-29T12:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Using timechat with 2 fields without any field calculation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-timechat-with-2-fields-without-any-field-calculation/m-p/252969#M175849</link>
      <description>&lt;P&gt;Have you tried just this: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=controlup sourcetype="csv-sessions" User="XPTO" 
| timechart span=60m avg("Protocol Latency _ Session Avg")  avg(CPU)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You can specify multiple stats in a timechart&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 12:57:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-timechat-with-2-fields-without-any-field-calculation/m-p/252969#M175849</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2017-01-26T12:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: Using timechat with 2 fields without any field calculation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-timechat-with-2-fields-without-any-field-calculation/m-p/252970#M175850</link>
      <description>&lt;P&gt;After several attemps I have my timeline like this:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2369i4BD6AEC865A41707/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel&amp;gt;
  &amp;lt;title&amp;gt;User timeline&amp;lt;/title&amp;gt;
  &amp;lt;input type="text" token="username_field1" searchWhenChanged="true"&amp;gt;
    &amp;lt;label&amp;gt;Username&amp;lt;/label&amp;gt;
    &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
    &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
  &amp;lt;/input&amp;gt;
  &amp;lt;input type="time" token="dash_date1" searchWhenChanged="true"&amp;gt;
    &amp;lt;label&amp;gt;Date&amp;lt;/label&amp;gt;
    &amp;lt;default&amp;gt;
      &amp;lt;earliest&amp;gt;@d&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;/default&amp;gt;
  &amp;lt;/input&amp;gt;
  &amp;lt;chart&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;
        index=pt_app_it_citrix_controlup sourcetype="csv-sessions" User="$username_field1$"
        | rex field=source ".*_(?&amp;lt;![CDATA[&amp;lt;date&amp;gt;]]&amp;gt;[0-9]+_[0-9]+_[0-9]+)_[0-9]+_[0-9]+_[0-9]+.csv" 
        | rex field=source ".*_(?&amp;lt;![CDATA[&amp;lt;hour&amp;gt;]]&amp;gt;[0-9]+_[0-9]+)_[0-9]+.csv"
        | eval _time = strptime(replace(date,"_","-") + " " + replace(hour,"_",":")+":00", "%m-%d-%Y %H:%M:%S")
        | timechart span=60m eval(round(avg('Protocol Latency _ Session Avg'),1)) as latency, eval(round(avg(CPU)/100,1)) as cpu
        | sort _time
    &amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;$dash_date1.earliest$&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;$dash_date1.latest$&amp;lt;/latest&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="charting.chart"&amp;gt;line&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.showDataLabels"&amp;gt;all&amp;lt;/option&amp;gt;
  &amp;lt;/chart&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But I still have to apply the AVG:&lt;BR /&gt;
    | timechart span=60m eval(round(avg('Protocol Latency _ Session Avg'),1)) as latency, eval(round(avg(CPU)/100,1)) as cpu&lt;/P&gt;

&lt;P&gt;Is there anyway to put these values As Is on a Timechart without the AVG ?&lt;/P&gt;

&lt;P&gt;Thanks !!!&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 14:49:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-timechat-with-2-fields-without-any-field-calculation/m-p/252970#M175850</guid>
      <dc:creator>fariapm1</dc:creator>
      <dc:date>2017-01-26T14:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: Using timechat with 2 fields without any field calculation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-timechat-with-2-fields-without-any-field-calculation/m-p/252971#M175851</link>
      <description>&lt;P&gt;Give this a try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=pt_app_it_citrix_controlup sourcetype="csv-sessions" User="$username_field1$"
| rex field=source ".*_(?&amp;lt;![CDATA[&amp;lt;timestamp&amp;gt;]]&amp;gt;\d{2}_\d{2}_\d{4}_\d{2}_\d{2}.csv" 
| eval _time = strptime(timestamp,"%m-%d-%Y %H:%M")
| table _time 'Protocol Latency _ Session Avg' CPU
| sort _time
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 13 Feb 2017 04:41:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-timechat-with-2-fields-without-any-field-calculation/m-p/252971#M175851</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-02-13T04:41:47Z</dc:date>
    </item>
  </channel>
</rss>

