<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Timecharting multiple lines..! in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128230#M34813</link>
    <description>&lt;P&gt;You have the correct search but your input file is NOT a &lt;CODE&gt;csv&lt;/CODE&gt;, it is a &lt;CODE&gt;tsv&lt;/CODE&gt;, which Splunk cannot handle directly on-the-fly. You can handle it by adding a full-blown &lt;CODE&gt;monitor&lt;/CODE&gt; input with &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and &lt;CODE&gt;props.conf&lt;/CODE&gt; (which &lt;EM&gt;can&lt;/EM&gt; be programmed to tell Splunk it is a tsv) or you can change the file by swapping the tabs for commas; then it will work.  Short of that, we have to start from scratch and work with the &lt;CODE&gt;_raw&lt;/CODE&gt; event because the automatic &lt;CODE&gt;csv&lt;/CODE&gt;-based field extractions are hopelessly broken.&lt;/P&gt;

&lt;P&gt;Ignoring the timestamp, you can make it work like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| inputlookup foo.csv | rex "(?&amp;lt;DATACENTER&amp;gt;\S+\s+\S+)\s+(?&amp;lt;METRIC_DATE&amp;gt;\S+)\s+(?&amp;lt;USEDPCT&amp;gt;.*)" | stats max(USEDPCT) BY DATACENTER
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Trying to use time, this &lt;EM&gt;should&lt;/EM&gt; work:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| inputlookup foo.csv | rex "(?&amp;lt;DATACENTER&amp;gt;\S+\s+\S+)\s+(?&amp;lt;METRIC_DATE&amp;gt;\S+)\s+(?&amp;lt;USEDPCT&amp;gt;.*)" | eval _time=METRIC_DATE | timechart span=86400s max(USEDPCT) BY DATACENTER
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 17 Jul 2015 16:46:04 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-07-17T16:46:04Z</dc:date>
    <item>
      <title>Timecharting multiple lines..!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128225#M34808</link>
      <description>&lt;P&gt;Hello, I have a question regarding timecharting multiple lines on one chart by Datacenter, but x-axis being Metric time and Y-axis being usedpct.&lt;/P&gt;

&lt;P&gt;DATACENTER  METRIC_DATE     USEDPCT&lt;BR /&gt;
Seoul, Korea    1393390800.000  59.1&lt;BR /&gt;
Busan, Korea    1393390800.000  5.6&lt;BR /&gt;
Seoul, Korea    1393477200.000  62.4&lt;BR /&gt;
Busan, Korea    1393477200.000  5.31&lt;BR /&gt;
Seoul, Korea    1393563600.000  59.4&lt;BR /&gt;
Busan, Korea    1393563600.000  3.66&lt;BR /&gt;
...&lt;BR /&gt;
How could I accomplish this?&lt;/P&gt;

&lt;P&gt;|inputlookup foo.csv|timechart span=86400s max(USEDPCT) by DATACENTER gives me no result for some reason&lt;/P&gt;

&lt;P&gt;I would appreciate your help-&lt;/P&gt;

&lt;P&gt;Jack&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 16:14:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128225#M34808</guid>
      <dc:creator>minkyuk</dc:creator>
      <dc:date>2015-07-17T16:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Timecharting multiple lines..!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128226#M34809</link>
      <description>&lt;P&gt;The problem is with your data. You have commas &lt;CODE&gt;,&lt;/CODE&gt; in the Datacenter field. Which in effect makes &lt;CODE&gt;DATACENTER&lt;/CODE&gt; equal to Seoul or Busan and Metric_date equal to Korea.&lt;/P&gt;

&lt;P&gt;You can fix this by updating the header of the CSV file to &lt;CODE&gt;dc_city,dc_country,metric_date,usedpct&lt;/CODE&gt;, and then do this search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|inputlookup foo.csv|eval DATACENTER = dc_city.", ".dc_country | timechart span=86400s max(USEDPCT) by DATACENTER
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you don't want to change the header, then you need to change the data.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"Seoul, Korea", 1393563600.000, 59.4
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 17 Jul 2015 16:30:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128226#M34809</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2015-07-17T16:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: Timecharting multiple lines..!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128227#M34810</link>
      <description>&lt;P&gt;My datacenter string is already "Seoul, Korea" so I'm assuming it's treated as one..&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 16:33:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128227#M34810</guid>
      <dc:creator>minkyuk</dc:creator>
      <dc:date>2015-07-17T16:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: Timecharting multiple lines..!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128228#M34811</link>
      <description>&lt;P&gt;I suspect that Splunk does not know that "METRIC_DATE" is a time parameter.  Try it this way:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| inputlookup foo.csv | rename METRIC_DATE as _time | timechart span=1d max(USEDPCT) by DATACENTER
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 17 Jul 2015 16:33:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128228#M34811</guid>
      <dc:creator>jimodonald</dc:creator>
      <dc:date>2015-07-17T16:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Timecharting multiple lines..!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128229#M34812</link>
      <description>&lt;P&gt;Thank you, got it to work.&lt;BR /&gt;
By any chance, I'm getting OTHER field since I have 10+ different datacenters, but how could I drill-down or change settings to prevent Splunk from making OTHER automatically&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 16:36:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128229#M34812</guid>
      <dc:creator>minkyuk</dc:creator>
      <dc:date>2015-07-17T16:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: Timecharting multiple lines..!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128230#M34813</link>
      <description>&lt;P&gt;You have the correct search but your input file is NOT a &lt;CODE&gt;csv&lt;/CODE&gt;, it is a &lt;CODE&gt;tsv&lt;/CODE&gt;, which Splunk cannot handle directly on-the-fly. You can handle it by adding a full-blown &lt;CODE&gt;monitor&lt;/CODE&gt; input with &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and &lt;CODE&gt;props.conf&lt;/CODE&gt; (which &lt;EM&gt;can&lt;/EM&gt; be programmed to tell Splunk it is a tsv) or you can change the file by swapping the tabs for commas; then it will work.  Short of that, we have to start from scratch and work with the &lt;CODE&gt;_raw&lt;/CODE&gt; event because the automatic &lt;CODE&gt;csv&lt;/CODE&gt;-based field extractions are hopelessly broken.&lt;/P&gt;

&lt;P&gt;Ignoring the timestamp, you can make it work like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| inputlookup foo.csv | rex "(?&amp;lt;DATACENTER&amp;gt;\S+\s+\S+)\s+(?&amp;lt;METRIC_DATE&amp;gt;\S+)\s+(?&amp;lt;USEDPCT&amp;gt;.*)" | stats max(USEDPCT) BY DATACENTER
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Trying to use time, this &lt;EM&gt;should&lt;/EM&gt; work:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| inputlookup foo.csv | rex "(?&amp;lt;DATACENTER&amp;gt;\S+\s+\S+)\s+(?&amp;lt;METRIC_DATE&amp;gt;\S+)\s+(?&amp;lt;USEDPCT&amp;gt;.*)" | eval _time=METRIC_DATE | timechart span=86400s max(USEDPCT) BY DATACENTER
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 17 Jul 2015 16:46:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128230#M34813</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-17T16:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Timecharting multiple lines..!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128231#M34814</link>
      <description>&lt;P&gt;add useother=f to the timechart portion of your query. use limit=x to limit your results.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 16:58:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timecharting-multiple-lines/m-p/128231#M34814</guid>
      <dc:creator>dflodstrom</dc:creator>
      <dc:date>2015-07-17T16:58:33Z</dc:date>
    </item>
  </channel>
</rss>

