<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Visualization in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638363#M221244</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Giuseppe ,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your reply. But need help in final visualization part after table command&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Apr 2023 10:37:09 GMT</pubDate>
    <dc:creator>kirthika26</dc:creator>
    <dc:date>2023-04-03T10:37:09Z</dc:date>
    <item>
      <title>How to represent good visualization with the following fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638335#M221237</link>
      <description>&lt;P&gt;How to represent good visualization with the following fields&lt;/P&gt;
&lt;P&gt;DeviceID, Software Version (Eg 1.22.2222.34) , Software Version Release Date (2020-02-03 00:00:00) , Software Version last timestamp ( 2020-02-05 02:04:45) and Total_Days ( 2)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Total Days is the difference between&amp;nbsp;Software Version Release Date and&amp;nbsp;Software Version last timestamp.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Chart should cover all fields&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 15:07:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638335#M221237</guid>
      <dc:creator>kirthika26</dc:creator>
      <dc:date>2023-04-04T15:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: Visualization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638344#M221239</link>
      <description>&lt;P&gt;Depending what you are trying to see I would say you could use either a sankey or a parallel coordinates custom viz.&lt;/P&gt;&lt;P&gt;Sankey&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3112" target="_blank"&gt;https://splunkbase.splunk.com/app/3112&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Parallel Coordinates&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3137" target="_blank"&gt;https://splunkbase.splunk.com/app/3137&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 10:15:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638344#M221239</guid>
      <dc:creator>diogofgm</dc:creator>
      <dc:date>2023-04-03T10:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Visualization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638345#M221240</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254926"&gt;@kirthika26&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;are all the information in one event or in different events from different data sources?&lt;/P&gt;&lt;P&gt;could you share a sample of these events, eventually one or two from each data source?&lt;/P&gt;&lt;P&gt;because if they are in one event, you have only to display them using table and calculating the Total Days using eval.&lt;/P&gt;&lt;P&gt;If instead (as I suppose) they are in different data sources I have to correlate them.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 10:16:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638345#M221240</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-04-03T10:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Visualization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638353#M221241</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached sample gcusello.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;all from same sources&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 10:53:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638353#M221241</guid>
      <dc:creator>kirthika26</dc:creator>
      <dc:date>2023-04-03T10:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: Visualization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638361#M221243</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254926"&gt;@kirthika26&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry, I wasn't clear: I need some sample of the raw events in text mode, not screenshot.&lt;/P&gt;&lt;P&gt;Anyway, viewing your message, I suppose that you have data in a csv, did you already indexed in Splunk?&lt;/P&gt;&lt;P&gt;All the information seems to be in the same event, in this kind, you have only to use eval to calculate the date difference.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| eval Total_Days =round(strptime(timestamp,"%m/%d/%Y %H:%M")-strptime(releasetime,"%m/%d/%Y %H:%M"))/86400,2)
| table Device_ID VersionIP releasetime timestamp Total_Days
| rename 
   Device_ID AS DeviceID
   VersionIP  AS "Software Version"
   releasetime AS "Software Version Release Date"
   timestamp AS "Software Version last timestamp"
   Total_Days&lt;/LI-CODE&gt;&lt;P&gt;remember that to compare different dates and times, you have to convert them in epochtime.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 10:34:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638361#M221243</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-04-03T10:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: Visualization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638363#M221244</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Giuseppe ,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your reply. But need help in final visualization part after table command&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 10:37:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638363#M221244</guid>
      <dc:creator>kirthika26</dc:creator>
      <dc:date>2023-04-03T10:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: Visualization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638364#M221245</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254926"&gt;@kirthika26&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I renamed the columns and I rounded the Total_Days field&lt;/P&gt;&lt;P&gt;what else you would add in final visualization?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 10:39:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638364#M221245</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-04-03T10:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: Visualization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638366#M221246</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 10:52:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638366#M221246</guid>
      <dc:creator>kirthika26</dc:creator>
      <dc:date>2023-04-03T10:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: Visualization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638368#M221248</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254926"&gt;@kirthika26&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if one answer solves your need, please accept one answer for the other people of Community or tell us how we can help you.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the Contributors;-)&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 10:55:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-represent-good-visualization-with-the-following-fields/m-p/638368#M221248</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-04-03T10:55:52Z</dc:date>
    </item>
  </channel>
</rss>

