I've managed to create charts happily from an index to a flat file with inputs from a dashboard;
|where field ="$inpfield$"
|chart count by "Range" | rename count as "Number"
But can this also be made when the data source is from dbquery? I cannot manage the same with similar below?
dbquery "select field1, field2 FROM table1 WHERE field ="$inpfield$"... "
| chart count by "field1"
yes you can apply regular splunk stats or chart or timechart commands to the results of a dbquery.
Just double check that your fields name and case are correct before.
View solution in original post
Actually, it was CASE issue, thanks - although the base dbquery is lower case, the chart syntax requires UPPER.
dbquery "select field1, field2 FROM table1 WHERE field ="$inpfield$"... " | chart count by "FIELD1"
Hi, that's what I was hoping, but I cant seem to pipe the results through to the chart? The first query returns results.
But when I apply the chart clause it does not return anything?
| dbquery "Oracle" "select username, common from all_users" | chart count by "common"
Would you have any syntax examples at all? Many Thanks