<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding sparklines to chart in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Adding-sparklines-to-chart/m-p/186730#M53762</link>
    <description>&lt;P&gt;You need to add the sparkline function to the chart command.  See below.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=techmon sourcetype="techmon_hpom_messages_history" | chart sparkline count by NODE_NAME,SEVERITY | addTOTALS labelfield=SEVERITY label=Total| sort -Total| head 20
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 13 May 2015 00:50:36 GMT</pubDate>
    <dc:creator>jimodonald</dc:creator>
    <dc:date>2015-05-13T00:50:36Z</dc:date>
    <item>
      <title>Adding sparklines to chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-sparklines-to-chart/m-p/186729#M53761</link>
      <description>&lt;P&gt;Hi, I have a chart that is a count of alerts by hostname and severity. I'd like to add a column that is a sparkline of alerts by time for each host. Here is my search and a screenshot of my chart with desired outcome. Help please?&lt;/P&gt;

&lt;P&gt;index=techmon sourcetype="techmon_hpom_messages_history" | chart count by NODE_NAME,SEVERITY | addTOTALS labelfield=SEVERITY label=Total| sort -Total| head 20&lt;/P&gt;

&lt;P&gt;Apparently need more splunk karma to post an attachment or a link so I will type out the chart here:&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;NODE_NAME  | Critical | Major | Minor | Normal | Warning | Total |&lt;/P&gt;

&lt;P&gt;Host 1 &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp | 5  &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp    |   3    &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp   | 10  &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp     |    0 &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp       |     8   &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp        |   36    |&lt;BR /&gt;
Host 2 &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp             |      1   &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp   |   3   &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp    | 6    &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp       |     3    &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp    |     8      &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp       |   19    |&lt;BR /&gt;
Host 3 &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp             |      2   &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp   |   6   &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp    | 0      &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp     |       5 &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp     |     2      &amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp&amp;amp;nbsp       |   15    |&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;I want to add Sparkline after total that will graph the alerts over time. The field for the time is LOCAL_RECEIVING_TIME.&lt;/P&gt;

&lt;P&gt;Thanks folks&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:53:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-sparklines-to-chart/m-p/186729#M53761</guid>
      <dc:creator>cjenning</dc:creator>
      <dc:date>2020-09-28T19:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: Adding sparklines to chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-sparklines-to-chart/m-p/186730#M53762</link>
      <description>&lt;P&gt;You need to add the sparkline function to the chart command.  See below.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=techmon sourcetype="techmon_hpom_messages_history" | chart sparkline count by NODE_NAME,SEVERITY | addTOTALS labelfield=SEVERITY label=Total| sort -Total| head 20
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 13 May 2015 00:50:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-sparklines-to-chart/m-p/186730#M53762</guid>
      <dc:creator>jimodonald</dc:creator>
      <dc:date>2015-05-13T00:50:36Z</dc:date>
    </item>
    <item>
      <title>Re: Adding sparklines to chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-sparklines-to-chart/m-p/186731#M53763</link>
      <description>&lt;P&gt;Thanks, but is there a way to do this so the sparklines are charted only by NODE_NAME while the count is by NODE_NAME and SEVERITY? In your solution I end up with 5 columns of sparklines.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:53:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-sparklines-to-chart/m-p/186731#M53763</guid>
      <dc:creator>cjenning</dc:creator>
      <dc:date>2020-09-28T19:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: Adding sparklines to chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-sparklines-to-chart/m-p/186732#M53764</link>
      <description>&lt;P&gt;Which field do you want to be used for the sparkline?&lt;/P&gt;

&lt;P&gt;BTW, the docs describe how to do this pretty well.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/Search/AddSparklinestoSearchResults"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.3/Search/AddSparklinestoSearchResults&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 01:16:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-sparklines-to-chart/m-p/186732#M53764</guid>
      <dc:creator>jimodonald</dc:creator>
      <dc:date>2015-05-14T01:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: Adding sparklines to chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-sparklines-to-chart/m-p/186733#M53765</link>
      <description>&lt;P&gt;I want the sparkline to be used for the total column. I tried going through that documentation but it didn't help me with this problem. Anyway I formulate my search I either get 5 sparklines or a chart way off from what I'm looking for with 1 broken sparkline. &lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 15:02:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-sparklines-to-chart/m-p/186733#M53765</guid>
      <dc:creator>cjenning</dc:creator>
      <dc:date>2015-05-14T15:02:33Z</dc:date>
    </item>
  </channel>
</rss>

