All Apps and Add-ons

Visualization question: Column vs Line chart

jonydupre
Path Finder

Hi,

I currently have a search which counts each unhealthy system for a set number of days. The idea is to get an idea if the numbers are increasing or decreasing. Currently I have a Column chart visualization, but I rather have a Line chart which give more of a visual perspective of the situation. This is the search:

index=linux  earliest=-1d@d latest=@d "healthcheck: System not healthy" | dedup host | stats count by host
| stats count as TotalA
| appendcols 
[search index=linux earliest=@d latest=now "healthcheck: System not healthy" | dedup host | stats count by host 
| stats count as TotalB]
| appendcols 
[search index=linux earliest=-2d@d latest=-1d@d "healthcheck: System not healthy" | dedup host | stats count by host 
| stats count as TotalC]
| appendcols 
[search index=linux earliest=-3d@d latest=-2d@d "healthcheck: System not healthy" | dedup host | stats count by host
| stats count as TotalD]
| appendcols 
[search index=linux earliest=-4d@d latest=-3d@d "healthcheck: System not healthy" | dedup host | stats count by host 
| stats count as TotalE]       
| eval Yesterday=TotalA 
| eval Today=TotalB
| eval Daybeforeyesterday=TotalC
| eval Daybeforethat=TotalD
| eval Daybeforethat1=TotalE
| fields HealthchecksError, Daybeforethat1, Daybeforethat, Daybeforeyesterday, Yesterday, Today

alt text

That's an example of the current visualization. Any idea which one I should choose or what I should change in the search? I can't get one to work..

Thanks a lot!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...