Hi Team,
I am new to Splunk and I am trying to exploit it.
I have Data which has [timestamp, WorkName ='', JobName='', Duration='']. I have 190 WorkName values and 1400 JobName Values. I am trying to visualize the runtime for WorkName. The search I have used: source="tem.log" sourcetype="Temp"| timechart avg(Duration) by WorkName
.
But in the visualization, it gives me just top 10 WorkName based on highest Duration and it puts rest 180 under one roof 'Others'.
Is there any way, where in I can have drop-down to select the WorkName to display its trends?
Thanks,
Sneha
Try using the limit
parameter:
source="tem.log" sourcetype="Temp"
| timechart avg(Duration) by WorkName limit=200 useother=f
That should give you 200 separate series. One thing to consider is that there's a limit of 100 series visualized at once in a line/area chart. One way around this is to use the Trellis function if you use Splunk 6.6. That would create a separate graph for each of the 200 series that you can page through.
If you want to go down the dropdown route I'd recommend setting up a dashboard that has
source="tem.log" sourcetype="Temp" | stats count by WorkName
)like so:
source="tem.log" sourcetype="Temp"
| where WorkName="$WorknameTokenFromFormInput$"
| timechart avg(Duration) by WorkName
Download this app and poke around:
Splunk 6.x Dashboard Examples: https://splunkbase.splunk.com/app/1603/
Try using the limit
parameter:
source="tem.log" sourcetype="Temp"
| timechart avg(Duration) by WorkName limit=200 useother=f
That should give you 200 separate series. One thing to consider is that there's a limit of 100 series visualized at once in a line/area chart. One way around this is to use the Trellis function if you use Splunk 6.6. That would create a separate graph for each of the 200 series that you can page through.
If you want to go down the dropdown route I'd recommend setting up a dashboard that has
source="tem.log" sourcetype="Temp" | stats count by WorkName
)like so:
source="tem.log" sourcetype="Temp"
| where WorkName="$WorknameTokenFromFormInput$"
| timechart avg(Duration) by WorkName