<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to display the values of a field in a chart, not the count of the number of events? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-values-of-a-field-in-a-chart-not-the-count-of/m-p/154387#M43429</link>
    <description>&lt;P&gt;Hello ! I have a field called Total Value that contains currency values ​​. &lt;/P&gt;

&lt;P&gt;I want to use these values ​​in my chart , however Splunk is counting the events , and not the values ​​themselves . &lt;/P&gt;

&lt;P&gt;How do I change this ? For example : Value = Total Value&lt;/P&gt;</description>
    <pubDate>Tue, 07 Oct 2014 12:37:41 GMT</pubDate>
    <dc:creator>MENININHU</dc:creator>
    <dc:date>2014-10-07T12:37:41Z</dc:date>
    <item>
      <title>How to display the values of a field in a chart, not the count of the number of events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-values-of-a-field-in-a-chart-not-the-count-of/m-p/154387#M43429</link>
      <description>&lt;P&gt;Hello ! I have a field called Total Value that contains currency values ​​. &lt;/P&gt;

&lt;P&gt;I want to use these values ​​in my chart , however Splunk is counting the events , and not the values ​​themselves . &lt;/P&gt;

&lt;P&gt;How do I change this ? For example : Value = Total Value&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 12:37:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-values-of-a-field-in-a-chart-not-the-count-of/m-p/154387#M43429</guid>
      <dc:creator>MENININHU</dc:creator>
      <dc:date>2014-10-07T12:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to display the values of a field in a chart, not the count of the number of events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-values-of-a-field-in-a-chart-not-the-count-of/m-p/154388#M43430</link>
      <description>&lt;P&gt;Can you post some sample events and may be current non-working search? Also, expected output.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 22:33:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-values-of-a-field-in-a-chart-not-the-count-of/m-p/154388#M43430</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-10-07T22:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to display the values of a field in a chart, not the count of the number of events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-values-of-a-field-in-a-chart-not-the-count-of/m-p/154389#M43431</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;
if your problem is to display values of the field Total values in your chart use a values() fonction after renaming Total values as Total_values&lt;BR /&gt;
|chart values(Toatal_values) &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:26:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-values-of-a-field-in-a-chart-not-the-count-of/m-p/154389#M43431</guid>
      <dc:creator>btt</dc:creator>
      <dc:date>2020-09-28T18:26:01Z</dc:date>
    </item>
  </channel>
</rss>

