All Apps and Add-ons

Basic Chart Issue

edschembor
Path Finder

So, I'm probably blanking on something, but I'm just trying to create a bar chart for a single value. So:

index=hpov eph " error " AND (tag="EPH_SVR") | chart count

But for some reason the bar graph won't appear. The reason I'm doing this is that I then have a larger search which appends columns, and for some reason, the first value (error count) won't appear as a bar and instead appears as the x-axis.

Thanks for the help!

0 Karma
1 Solution

somesoni2
Revered Legend

For plotting a chart your need 2 columns for both x an y axis. You search is producing just one.

Try something like this

index=hpov eph " error " AND (tag="EPH_SVR") | eval metric="Errors" | chart count by metric

View solution in original post

somesoni2
Revered Legend

For plotting a chart your need 2 columns for both x an y axis. You search is producing just one.

Try something like this

index=hpov eph " error " AND (tag="EPH_SVR") | eval metric="Errors" | chart count by metric

edschembor
Path Finder

Nvm, solved it with:

index=hpov eph " error " AND (tag="EPH_SVR") | eval ReasonForFailure="" | chart count as error by ReasonForFailure | appendcols [ search index=hpov eph " fatal " AND (tag="EPH_SVR") | stats count as fatal]

0 Karma

edschembor
Path Finder

But what about the second part? When I switch to a larger search:

index=hpov eph " error " AND (tag="EPH_SVR") | eval errCount="Errors" | chart count by errCount | appendcols [search index=hpov eph " exception " AND (tag="EPH_SVR")| stats count as exception]| appendcols [search index=hpov eph " EXCEPTION " AND (tag="EPH_SVR") | stats count as exception]

Then the x-axis is errCount and when I hover over a bar i get "errCount: Errors"

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...