<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do I show search value with timechart? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-show-search-value-with-timechart/m-p/590344#M205537</link>
    <description>&lt;P&gt;Dear professionals,&lt;BR /&gt;&lt;BR /&gt;I have a search string like this&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="hcg_oapi_prod" relatedPersons NOT (firstName OR middleName OR lastName) | regex "\"relatedPersons\":\[\]"&lt;/LI-CODE&gt;
&lt;P&gt;And this is the result. The results have "&lt;SPAN&gt;bankAccount&lt;/SPAN&gt;" value.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lamnguyentt1_0-1648019147433.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18697iF5D8E8C3562B692F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lamnguyentt1_0-1648019147433.png" alt="lamnguyentt1_0-1648019147433.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Then I add timechart like this&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="hcg_oapi_prod" relatedPersons NOT (firstName OR middleName OR lastName)
| regex "\"relatedPersons\":\[\]"
|timechart span=1m count as today
|fields today&lt;/LI-CODE&gt;
&lt;P&gt;How can I add a column for &lt;SPAN&gt;bankAccount when today = 1?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk-3.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18698i0195A3F434DA8BD9/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk-3.PNG" alt="splunk-3.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Wed, 23 Mar 2022 14:24:41 GMT</pubDate>
    <dc:creator>lamnguyentt1</dc:creator>
    <dc:date>2022-03-23T14:24:41Z</dc:date>
    <item>
      <title>How do I show search value with timechart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-show-search-value-with-timechart/m-p/590344#M205537</link>
      <description>&lt;P&gt;Dear professionals,&lt;BR /&gt;&lt;BR /&gt;I have a search string like this&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="hcg_oapi_prod" relatedPersons NOT (firstName OR middleName OR lastName) | regex "\"relatedPersons\":\[\]"&lt;/LI-CODE&gt;
&lt;P&gt;And this is the result. The results have "&lt;SPAN&gt;bankAccount&lt;/SPAN&gt;" value.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lamnguyentt1_0-1648019147433.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18697iF5D8E8C3562B692F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lamnguyentt1_0-1648019147433.png" alt="lamnguyentt1_0-1648019147433.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Then I add timechart like this&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="hcg_oapi_prod" relatedPersons NOT (firstName OR middleName OR lastName)
| regex "\"relatedPersons\":\[\]"
|timechart span=1m count as today
|fields today&lt;/LI-CODE&gt;
&lt;P&gt;How can I add a column for &lt;SPAN&gt;bankAccount when today = 1?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk-3.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18698i0195A3F434DA8BD9/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk-3.PNG" alt="splunk-3.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 14:24:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-show-search-value-with-timechart/m-p/590344#M205537</guid>
      <dc:creator>lamnguyentt1</dc:creator>
      <dc:date>2022-03-23T14:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Show search value with timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-show-search-value-with-timechart/m-p/590347#M205540</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240782"&gt;@lamnguyentt1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;there's something not clear for me in your search: why do you extract "relatedPersons" field if you don't use in timechart?&lt;/P&gt;&lt;P&gt;Rememeber that after a transaction command (as stats or timechart), you have only the fields in the command, in your case only _time and count renamed in today.&lt;/P&gt;&lt;P&gt;If you want more fields you have to put them in the command, e.g.:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="hcg_oapi_prod" relatedPersons NOT (firstName OR middleName OR lastName)
| timechart span=1m count as today BY bankAccount&lt;/LI-CODE&gt;&lt;P&gt;If you want more fields (e.g.&amp;nbsp;&lt;SPAN&gt;relatedPersons), you have to use bin and stats, something like this:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="hcg_oapi_prod" relatedPersons NOT (firstName OR middleName OR lastName)
| regex "\"relatedPersons\":\[\]"
| bin span=1m _time
| stats values(relatedPersons) AS relatedPersons count as today BY bankAccount&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 07:40:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-show-search-value-with-timechart/m-p/590347#M205540</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-03-23T07:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Show search value with timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-show-search-value-with-timechart/m-p/590348#M205541</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240782"&gt;@lamnguyentt1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) i think the regex is not needed as you filter that on first line itself.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) timechart requires a "BY" clause i think.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check this one:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="hcg_oapi_prod" relatedPersons NOT (firstName OR middleName OR lastName)
|timechart span=1m count as today BY host
|fields today&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 23 Mar 2022 07:40:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-show-search-value-with-timechart/m-p/590348#M205541</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2022-03-23T07:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Show search value with timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-show-search-value-with-timechart/m-p/590359#M205545</link>
      <description>&lt;P&gt;Dear Mr.&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For clearly,&lt;/P&gt;&lt;P&gt;The origin search is&amp;nbsp;&lt;/P&gt;&lt;P&gt;index="hcg_oapi_prod" relatedPersons&lt;/P&gt;&lt;P&gt;And this is results&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lamnguyentt1_1-1648024296300.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18700i4C0F486CC8A666C9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lamnguyentt1_1-1648024296300.png" alt="lamnguyentt1_1-1648024296300.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to create the alert when it matches this condition&lt;/P&gt;&lt;P&gt;1. The results have&amp;nbsp;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;relatedPersons&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;[] and don't have&amp;nbsp;(firstName OR middleName OR lastName)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. I will count the search result each 1 minute if count &amp;gt;1, I will send an email and I want to attach&amp;nbsp;&amp;nbsp;"&lt;SPAN class=""&gt;bankAccount value (for other person easy to search when they receive the email)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have use your search string but it shows that&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lamnguyentt1_2-1648024553765.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18701iE597270E4EA1FBA7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lamnguyentt1_2-1648024553765.png" alt="lamnguyentt1_2-1648024553765.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please help me, print result like this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="splunk-3.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18702i15435ACDF5812CEB/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk-3.PNG" alt="splunk-3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 08:36:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-show-search-value-with-timechart/m-p/590359#M205545</guid>
      <dc:creator>lamnguyentt1</dc:creator>
      <dc:date>2022-03-23T08:36:55Z</dc:date>
    </item>
  </channel>
</rss>

