<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I recreate this chart in Splunk? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254199#M76109</link>
    <description>&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/129195-splunk.jpg" alt="alt text" /&gt;&lt;BR /&gt;
&lt;A href="http://imgur.com/MbH4w37" target="_blank"&gt;http://imgur.com/MbH4w37&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Trying to recreate this chart in Splunk - can anyone assist, as I'm a bit uncertain where to start?&lt;/P&gt;

&lt;P&gt;Hits = SampleCount&lt;BR /&gt;
Network Time = Network Time&lt;BR /&gt;
Server Time = Server Time&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Field   Value   Actions
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Selected&lt;BR /&gt;&lt;BR /&gt;
Location&lt;BR /&gt;
Sydney&lt;BR /&gt;&lt;BR /&gt;
Time&lt;BR /&gt;
6:35:54 AM&lt;BR /&gt;&lt;BR /&gt;
host&lt;BR /&gt;
SPLUNK&lt;BR /&gt;&lt;BR /&gt;
index&lt;BR /&gt;
main&lt;BR /&gt;&lt;BR /&gt;
source&lt;BR /&gt;
Filtered_data_Peak3.csv &lt;BR /&gt;
sourcetype&lt;BR /&gt;
csv &lt;BR /&gt;
Event&lt;BR /&gt;&lt;BR /&gt;
ErrorCount&lt;BR /&gt;
0&lt;BR /&gt;&lt;BR /&gt;
Network Time&lt;BR /&gt;
175 &lt;BR /&gt;
Response Time&lt;BR /&gt;
533 &lt;BR /&gt;
SampleCount&lt;BR /&gt;
1&lt;BR /&gt;&lt;BR /&gt;
Server Time&lt;BR /&gt;
358 &lt;BR /&gt;
URL&lt;BR /&gt;
&lt;A href="https://xxxxxx" target="_blank"&gt;https://xxxxxx&lt;/A&gt;&lt;BR /&gt;
331 &lt;BR /&gt;
bytes&lt;BR /&gt;
473 &lt;BR /&gt;
grpThreads&lt;BR /&gt;
331 &lt;BR /&gt;
label&lt;BR /&gt;
/data_table.do&lt;BR /&gt;&lt;BR /&gt;
linecount&lt;BR /&gt;
1&lt;BR /&gt;&lt;BR /&gt;
responseCode&lt;BR /&gt;
200 &lt;BR /&gt;
splunk_server&lt;BR /&gt;
SPLUNK&lt;BR /&gt;&lt;BR /&gt;
success&lt;BR /&gt;
1&lt;BR /&gt;&lt;BR /&gt;
timeStamp&lt;BR /&gt;
1.46355E+12 &lt;BR /&gt;
Time&lt;BR /&gt;&lt;BR /&gt;
&lt;EM&gt;time&lt;BR /&gt;
2016-05-19T06:35:54.000+10:00&lt;BR /&gt;&lt;BR /&gt;
Default &lt;BR /&gt;
punct&lt;BR /&gt;
.+,::&lt;/EM&gt;,,,,,/.,,,,,,://.-./.?=&amp;amp;=&amp;amp;=&amp;amp;=&amp;amp;=,,&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 09:43:39 GMT</pubDate>
    <dc:creator>Esky73</dc:creator>
    <dc:date>2020-09-29T09:43:39Z</dc:date>
    <item>
      <title>How can I recreate this chart in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254199#M76109</link>
      <description>&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/129195-splunk.jpg" alt="alt text" /&gt;&lt;BR /&gt;
&lt;A href="http://imgur.com/MbH4w37" target="_blank"&gt;http://imgur.com/MbH4w37&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Trying to recreate this chart in Splunk - can anyone assist, as I'm a bit uncertain where to start?&lt;/P&gt;

&lt;P&gt;Hits = SampleCount&lt;BR /&gt;
Network Time = Network Time&lt;BR /&gt;
Server Time = Server Time&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Field   Value   Actions
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Selected&lt;BR /&gt;&lt;BR /&gt;
Location&lt;BR /&gt;
Sydney&lt;BR /&gt;&lt;BR /&gt;
Time&lt;BR /&gt;
6:35:54 AM&lt;BR /&gt;&lt;BR /&gt;
host&lt;BR /&gt;
SPLUNK&lt;BR /&gt;&lt;BR /&gt;
index&lt;BR /&gt;
main&lt;BR /&gt;&lt;BR /&gt;
source&lt;BR /&gt;
Filtered_data_Peak3.csv &lt;BR /&gt;
sourcetype&lt;BR /&gt;
csv &lt;BR /&gt;
Event&lt;BR /&gt;&lt;BR /&gt;
ErrorCount&lt;BR /&gt;
0&lt;BR /&gt;&lt;BR /&gt;
Network Time&lt;BR /&gt;
175 &lt;BR /&gt;
Response Time&lt;BR /&gt;
533 &lt;BR /&gt;
SampleCount&lt;BR /&gt;
1&lt;BR /&gt;&lt;BR /&gt;
Server Time&lt;BR /&gt;
358 &lt;BR /&gt;
URL&lt;BR /&gt;
&lt;A href="https://xxxxxx" target="_blank"&gt;https://xxxxxx&lt;/A&gt;&lt;BR /&gt;
331 &lt;BR /&gt;
bytes&lt;BR /&gt;
473 &lt;BR /&gt;
grpThreads&lt;BR /&gt;
331 &lt;BR /&gt;
label&lt;BR /&gt;
/data_table.do&lt;BR /&gt;&lt;BR /&gt;
linecount&lt;BR /&gt;
1&lt;BR /&gt;&lt;BR /&gt;
responseCode&lt;BR /&gt;
200 &lt;BR /&gt;
splunk_server&lt;BR /&gt;
SPLUNK&lt;BR /&gt;&lt;BR /&gt;
success&lt;BR /&gt;
1&lt;BR /&gt;&lt;BR /&gt;
timeStamp&lt;BR /&gt;
1.46355E+12 &lt;BR /&gt;
Time&lt;BR /&gt;&lt;BR /&gt;
&lt;EM&gt;time&lt;BR /&gt;
2016-05-19T06:35:54.000+10:00&lt;BR /&gt;&lt;BR /&gt;
Default &lt;BR /&gt;
punct&lt;BR /&gt;
.+,::&lt;/EM&gt;,,,,,/.,,,,,,://.-./.?=&amp;amp;=&amp;amp;=&amp;amp;=&amp;amp;=,,&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:43:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254199#M76109</guid>
      <dc:creator>Esky73</dc:creator>
      <dc:date>2020-09-29T09:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: How can I recreate this chart in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254200#M76110</link>
      <description>&lt;P&gt;Since your sourcetype is &lt;CODE&gt;csv&lt;/CODE&gt; I assume the fields have been extracted. Try this for your chart. You can set it up for display as an &lt;CODE&gt;area chart&lt;/CODE&gt; with Hits as &lt;CODE&gt;overlay&lt;/CODE&gt;.That should give you something similar to what you have.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base search here | timechart span=3m sum(SampleCount) as Hits sum("Network Time") as "Network Time" sum("Server Time") as "Server Time" 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 19 May 2016 12:26:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254200#M76110</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-05-19T12:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: How can I recreate this chart in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254201#M76111</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Thanks for looking at this ..  is there a way of using the "Time" field instead of _time ? &lt;/P&gt;

&lt;P&gt;Also how to add an average line onto the chart for average response time ?&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 14:01:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254201#M76111</guid>
      <dc:creator>Esky73</dc:creator>
      <dc:date>2016-05-19T14:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: How can I recreate this chart in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254202#M76112</link>
      <description>&lt;P&gt;Here...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base search here | timechart span=3m sum(SampleCount) as Hits sum("Network Time") as "Network Time" sum("Server Time") as "Server Time" avg("Response Time") as "Response Time" | rename _time AS Time | fieldformat Time=strftime(Time, "%x %X")
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 19 May 2016 14:37:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254202#M76112</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-05-19T14:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: How can I recreate this chart in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254203#M76113</link>
      <description>&lt;P&gt;Thanks, As the "Hits" (SampleTime) is using the left axis .. the line is right at the bottom of the chart as it is using those values to plot  - which is why i was looking for a separate axis on the right side to represent the hits to make it more presentable.&lt;/P&gt;

&lt;P&gt;Also for the bottom of the graph - all we are doing is re-naming _time to Time  - what i want to do is use the values for the Time Field for the bottom of the graph.&lt;/P&gt;

&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 23:56:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254203#M76113</guid>
      <dc:creator>Esky73</dc:creator>
      <dc:date>2016-05-19T23:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: How can I recreate this chart in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254204#M76114</link>
      <description>&lt;P&gt;For hits, you can specify a second axis for the overlay field (Hits). See here for how-to &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.8/Viz/Chartcontrols#Chart_overlay"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.8/Viz/Chartcontrols#Chart_overlay&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;For Time, try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base search here | eval Time=strptime(Time, "%H:%M:%S %p") | bin span=3m Time | chart sum(SampleCount) as Hits sum("Network Time") as "Network Time" sum("Server Time") as "Server Time" avg("Response Time") as "Response Time" by Time | fieldformat Time=strftime(Time, "%H:%M:%S %p")
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 20 May 2016 02:20:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254204#M76114</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-05-20T02:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: How can I recreate this chart in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254205#M76115</link>
      <description>&lt;P&gt;Thanks - i didn't need to use another Time - we got the _time working properly from the source - and the Overlay did the trick for the Hits Chart - thanks a lot for help, made my 1st Splunk venture a successful one &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2016 05:00:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254205#M76115</guid>
      <dc:creator>Esky73</dc:creator>
      <dc:date>2016-05-20T05:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: How can I recreate this chart in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254206#M76116</link>
      <description>&lt;P&gt;Glad you found your solution through @sundareshr's help. Don't forget to resolve the question by clicking "Accept" directly below his answer. Be sure to upvote his answer and/or comment that helped you too&lt;/P&gt;</description>
      <pubDate>Sat, 21 May 2016 21:11:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-recreate-this-chart-in-Splunk/m-p/254206#M76116</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2016-05-21T21:11:43Z</dc:date>
    </item>
  </channel>
</rss>

