Hi there, I am in the process of evaluating Splunk as a possible replacement to our existing data historian. Our users require a Stepped Line Graph for trending purposes rather than the conventional line graph. Is it possible to provide a Stepped Line Graph visualistion in Splunk?
Kind Regards
Paul J.
Not directly, but you can group data points by series and use the xyseries command to plot steps:
foo.csv
series,x,y
a,0,1
a,1,1
a,2,1
b,2,2
b,3,2
b,4,2
c,4,3
c,5,3
c,6,3
| inputlookup foo.csv
| xyseries x series y
x | a | b | c |
0 | 1 | ||
1 | 1 | ||
2 | 1 | 2 | |
3 | 2 | ||
4 | 2 | 3 | |
5 | 3 | ||
6 | 3 |
Splunk also provides an interface to develop custom visualizations: https://dev.splunk.com/enterprise/docs/developapps/visualizedata/displaydataview/splunkplatformcusto...
Thanks for the feedback, unfortunately, whilst this would work for specifically manipulated data content, in my particular case the stepped chart needs to be generated from a real-time data feed.
Kind Regards
Paul.
I used a contrived example, but streaming data can be modified into a similar structure using SPL. Search-time analysis and transformation is Splunk's core value proposition.