<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk report in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122409#M32953</link>
    <description>&lt;P&gt;Take a look at the solutions I've provided below. Let me know if that works for you.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Apr 2014 17:28:28 GMT</pubDate>
    <dc:creator>jhowkins</dc:creator>
    <dc:date>2014-04-10T17:28:28Z</dc:date>
    <item>
      <title>splunk report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122396#M32940</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have timeDif values(Time diffrence between start and stop) which I want to point in chart with time period.&lt;/P&gt;

&lt;P&gt;please help me.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2014 15:33:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122396#M32940</guid>
      <dc:creator>rameshlpatel</dc:creator>
      <dc:date>2014-04-07T15:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: splunk report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122397#M32941</link>
      <description>&lt;P&gt;Do elaborate more on your data and the desired results.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2014 17:40:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122397#M32941</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-07T17:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: splunk report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122398#M32942</link>
      <description>&lt;P&gt;I have the values(milliseconds) which I am getting from logs. In chart In X axis=Time period and in Y axis=milliseconds. &lt;/P&gt;

&lt;P&gt;In this i need line chart which goes up and down based on milliseconds value coming from logs.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2014 13:05:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122398#M32942</guid>
      <dc:creator>rameshlpatel</dc:creator>
      <dc:date>2014-04-08T13:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: splunk report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122399#M32943</link>
      <description>&lt;P&gt;So..... something like this?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;base search | timechart avg(milliseconds)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Set the visualization to line charts.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2014 13:21:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122399#M32943</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-08T13:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: splunk report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122400#M32944</link>
      <description>&lt;P&gt;Thanks for your answer,I tried but its not working.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2014 13:23:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122400#M32944</guid>
      <dc:creator>rameshlpatel</dc:creator>
      <dc:date>2014-04-08T13:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: splunk report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122401#M32945</link>
      <description>&lt;P&gt;In what way?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2014 13:24:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122401#M32945</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-08T13:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: splunk report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122402#M32946</link>
      <description>&lt;P&gt;Its not showing any line in chart&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2014 16:16:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122402#M32946</guid>
      <dc:creator>rameshlpatel</dc:creator>
      <dc:date>2014-04-08T16:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: splunk report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122403#M32947</link>
      <description>&lt;P&gt;Make sure you're using the correct field name in the &lt;CODE&gt;avg(fieldname)&lt;/CODE&gt; call.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2014 16:41:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122403#M32947</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-08T16:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: splunk report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122404#M32948</link>
      <description>&lt;P&gt;Yes I am doing..&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 11:40:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122404#M32948</guid>
      <dc:creator>rameshlpatel</dc:creator>
      <dc:date>2014-04-09T11:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: splunk report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122405#M32949</link>
      <description>&lt;P&gt;Could you please share your current query and sample output of that query? It would be lot easier to provide suggestion if we can see what you see.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 13:05:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122405#M32949</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-04-09T13:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: splunk report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122406#M32950</link>
      <description>&lt;P&gt;index="OCSDEV" | timechart avg(timeDiff)&lt;/P&gt;

&lt;P&gt;Here timeDiff ( in milliseconds) is field I am extracting from the logs.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 13:14:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122406#M32950</guid>
      <dc:creator>rameshlpatel</dc:creator>
      <dc:date>2014-04-09T13:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: splunk report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122407#M32951</link>
      <description>&lt;P&gt;Does that field contain numeric values?&lt;/P&gt;

&lt;P&gt;Posting some sample data would indeed make it a lot easier than stabbing in the dark.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 16:12:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122407#M32951</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-09T16:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: splunk report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122408#M32952</link>
      <description>&lt;P&gt;I suspect you're only getting single points on the linechart but they are not connected. If this is the case, try the following;&lt;/P&gt;

&lt;P&gt;Assuming you've already set your chart type to "Line"...&lt;BR /&gt;
 - Click "Format" to the upper left of the chart on the Visualization tab&lt;BR /&gt;
 - From the General tab, click the "Connect" button (right-most) next to "Null Values"&lt;BR /&gt;
 - Click Apply and your linechart will have connected dots&lt;/P&gt;

&lt;P&gt;If your events are not continuous, you could also acheive the same thing by setting cont=f ...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | timechart cont=f avg(timeDiff)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I've made some assumptions here. Hopefully I answered your question -- if not, I'd need more detail... a screenshot is always nice.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 17:56:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122408#M32952</guid>
      <dc:creator>jhowkins</dc:creator>
      <dc:date>2014-04-09T17:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: splunk report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122409#M32953</link>
      <description>&lt;P&gt;Take a look at the solutions I've provided below. Let me know if that works for you.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2014 17:28:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-report/m-p/122409#M32953</guid>
      <dc:creator>jhowkins</dc:creator>
      <dc:date>2014-04-10T17:28:28Z</dc:date>
    </item>
  </channel>
</rss>

