<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I create a Gantt chart to show work hours by person in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39787#M178832</link>
    <description>&lt;P&gt;I really like that user4, solid trooper, really goes the extra mile, not like bob at all in fact.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Aug 2012 21:57:14 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2012-08-20T21:57:14Z</dc:date>
    <item>
      <title>How do I create a Gantt chart to show work hours by person</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39783#M178828</link>
      <description>&lt;P&gt;I want to create a gantt chart to show by day who was working when.  My record layout is start timestamp (12/08/20.05:45:06) end timestamp (12/08/20.05:45:43) person(bob).  The goal is to visualize everyone for example 9-11 or 10-12, etc. &lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2012 20:41:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39783#M178828</guid>
      <dc:creator>bsteph</dc:creator>
      <dc:date>2012-08-20T20:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create a Gantt chart to show work hours by person</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39784#M178829</link>
      <description>&lt;P&gt;sample input would be nice....&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2012 20:43:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39784#M178829</guid>
      <dc:creator>DTERM</dc:creator>
      <dc:date>2012-08-20T20:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create a Gantt chart to show work hours by person</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39785#M178830</link>
      <description>&lt;P&gt;bob does not seem to be putting in a lot of work. 37 seconds &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2012 21:08:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39785#M178830</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-08-20T21:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create a Gantt chart to show work hours by person</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39786#M178831</link>
      <description>&lt;P&gt;Here is some sample data&lt;/P&gt;

&lt;P&gt;12/08/20.09:00:28  12/08/20.13:05:28  user1&lt;BR /&gt;
12/08/20.10:05:28  12/08/20.15:05:29  user2&lt;BR /&gt;
12/08/20.08:02:34  12/08/20.14:05:51  user3&lt;BR /&gt;
12/08/20.09:00:27  12/08/20.20:06:05  user4&lt;BR /&gt;
12/08/20.09:06:08  12/08/20.19:06:24  user5&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2012 21:49:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39786#M178831</guid>
      <dc:creator>bsteph</dc:creator>
      <dc:date>2012-08-20T21:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create a Gantt chart to show work hours by person</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39787#M178832</link>
      <description>&lt;P&gt;I really like that user4, solid trooper, really goes the extra mile, not like bob at all in fact.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2012 21:57:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39787#M178832</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-08-20T21:57:14Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create a Gantt chart to show work hours by person</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39788#M178833</link>
      <description>&lt;P&gt;yeah, bob didn't really work out....&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2012 22:01:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39788#M178833</guid>
      <dc:creator>bsteph</dc:creator>
      <dc:date>2012-08-20T22:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create a Gantt chart to show work hours by person</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39789#M178834</link>
      <description>&lt;P&gt;Say you've extracted these timestamps and parsed the timestamp so you can get epoch time values. Let's also assume you only want to do this for 1 day windows, i.e. you are setting the timerange from midnight to midnight only, and no one works past midnight (if they do we are going to just chart it as if they did stop at midnight).&lt;/P&gt;

&lt;P&gt;We also need users to evaluate to numbers so they show up in a chart. You would do this with a uid lookup, that is a csv of username to uid something like:&lt;BR /&gt;
bob,1&lt;BR /&gt;
justin,2&lt;BR /&gt;
susan,3&lt;/P&gt;

&lt;P&gt;In this example the fields are clock_in, clock_out, user. What we'll do is expand the dataset so that we can chart on those timestamps. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | eval clock=clock_in + ":" + clock_out | lookup UserToUid user OUTPUT uid | makemv clock delim=":" | mvexpand clock | chart first(uid) as UserID by clock 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This is a hideous solution, what you really need is a custom module to get a custom visualization, but if you don't feel comfortable doing that this will work. &lt;/P&gt;

&lt;P&gt;Run this search to get an example of what this would look like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| stats count | eval clock="120"+":"+"130" | eval user="5" | makemv clock delim=":" | mvexpand clock | chart first(user) by clock
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 21 Aug 2012 20:39:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39789#M178834</guid>
      <dc:creator>tfletcher_splun</dc:creator>
      <dc:date>2012-08-21T20:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create a Gantt chart to show work hours by person</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39790#M178835</link>
      <description>&lt;P&gt;Sadly I've spent too much time thinking, guessing and testing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;However, I also have a fairly ugly solution, but it sort of works, at least for my (actually your) test data, with just one addition. More on that later. Here's a line by line walkthrough;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...| rex "\s(?&amp;lt;QQQ&amp;gt;[\S]+)" max_match=2 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The idea here is to extract the timestamps as a multivalued field (&lt;CODE&gt;QQQ&lt;/CODE&gt;). Since I didn't have the energy to make Splunk understand your timestamps, I added 2012-08-21T21:22:23 style timestamps first in each line. If I didn't Splunk ate the whole file as one event. This means that you might want to change the &lt;CODE&gt;rex&lt;/CODE&gt; to match a whitespace after the start/end timestamps like &lt;CODE&gt;rex "(?&amp;lt;QQQ&amp;gt;[\S]+)\s" max_match=2&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex "\s(?&amp;lt;UserID&amp;gt;[\w]+)$" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Extract the userId at the end of the line.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| stats list(QQQ) AS Q by UserID 
| mvexpand Q  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;List the timestamps by userID and then create 'new' events based on the multivalued fields, so that each new event one userID and one timestamp (regardless of wheter it's the start or end time)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval _time = strptime(Q,"%Y/%m/%d.%H:%M:%S")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;For each of those events, set the start- or end-time as the event's own _time&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| timechart span=1h first(_time) by UserID 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Create a chart.&lt;/P&gt;

&lt;P&gt;In order to get something even remotely like what you want, you should now take the full query and use it in the Advanced Charting wizard (Dashboards &amp;amp; Views -&amp;gt; Advanced Charting). &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex "\s(?&amp;lt;QQQ&amp;gt;[\S]+)" max_match=2 | rex "\s(?&amp;lt;UserID&amp;gt;[\w]+)$" | stats list(QQQ) AS Q by UserID | mvexpand Q  | eval _time = strptime(Q,"%Y/%m/%d.%H:%M:%S") | timechart span=1h first(_time) by UserID  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;UL&gt;
&lt;LI&gt;Paste the query, and in the menus;&lt;/LI&gt;
&lt;LI&gt;select Chart Type "line"&lt;/LI&gt;
&lt;LI&gt;select Multi-Series mode "Split"&lt;/LI&gt;
&lt;LI&gt;select Missing Values "Connected"&lt;/LI&gt;
&lt;LI&gt;Put the Legend on either "Right" or "Left"&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;This is still not very beautiful as the Y-axis must show the values of _time instead of the UserID, at least that's as far as I got. Also, I have a strong suspicion that it would simply not work for multiple sets per person per day. Actually I know it wouldn't, so from now on all lunches and coffee breaks are cancelled. &lt;/P&gt;

&lt;P&gt;Well, anyway I learned a lot of stuff that don't work... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps a little bit,&lt;/P&gt;

&lt;P&gt;Kristian&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2012 22:44:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39790#M178835</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-08-21T22:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create a Gantt chart to show work hours by person</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39791#M178836</link>
      <description>&lt;P&gt;Hooray for your effort.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2012 22:47:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-a-Gantt-chart-to-show-work-hours-by-person/m-p/39791#M178836</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-08-21T22:47:50Z</dc:date>
    </item>
  </channel>
</rss>

