Dashboards & Visualizations

want to combine time chart and table

oda
Communicator

I want to use timechart as instead of sparkline.

It is the current search sentence.

index=test | table A B C D | join A [ search index=test |

chart sparkline(max(B)) by A ] | makemv delim="," setsv=true sparkline(max(A))

Do you have any suggestions?

Thanks.
alt text

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Add _time to your table.

0 Karma

oda
Communicator

Thank you for answering. But,I would like to have a way like tableau.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Can you share a link or a screenshot of what you mean?

0 Karma

oda
Communicator

Thank you for contacting.
Could you check it because I added a screenshot?

0 Karma

jkat54
SplunkTrust
SplunkTrust
Try this

index=test |timechart max(A) max(B) max(C) max(D)
0 Karma

oda
Communicator

I appreciate your suggestion.
It is displayed in one figure, it is easy to see, but this time I want to display it separately.

For example, every host.

0 Karma

niketn
Legend

Do you want help with post Processing to run single base search for table and timechart? While displaying can you display timechart on click of a particular table row? If yes please check out Table Row Expansion (More Details) and In-Page Drilldown with Perma-linking examples in Splunk 6.x Dashboard Examples app

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

oda
Communicator

Thank you. I am glad your reply.However, I made that setting.It can display only one graph.I would like to have a way like tableau.Best regards.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...