Dashboards & Visualizations

How do I plot a trendline on a pivot chart

jeremiahc4
Builder

I am using Pivot to create a dashboard full of pretty charts. Some of these charts lend themselves to having a trendline drawn on them. However, I can't seem to plot a trendline in Pivot. Am I missing something obvious or is this an advanced scenario where I need to bust out the command reference and do it via normal search means?

0 Karma
1 Solution

mattness
Splunk Employee
Splunk Employee

Trendlines aren't available for the initial release of Pivot. You can use Pivot in conjunction with the old-school method of adding trendlines to charts by getting the pivot search string...

  • create your pretty chart in Pivot
  • add it to a dashboard
  • click Edit > Edit Panel and then click the pivot symbol and select Edit Search String. This reveals a simplified version of the pivot search that uses the pivot command. Eventually you may become familiar enough with the pivot command to code searches using it.

...and then using that search string in a larger search that uses the trendline command to plot a trendline. Or you could set up a dashboard panel that utilizes some tricksy implementation of chart overlay (pivot chart over trendline chart)...whatever works best for you.

View solution in original post

mattness
Splunk Employee
Splunk Employee

Trendlines aren't available for the initial release of Pivot. You can use Pivot in conjunction with the old-school method of adding trendlines to charts by getting the pivot search string...

  • create your pretty chart in Pivot
  • add it to a dashboard
  • click Edit > Edit Panel and then click the pivot symbol and select Edit Search String. This reveals a simplified version of the pivot search that uses the pivot command. Eventually you may become familiar enough with the pivot command to code searches using it.

...and then using that search string in a larger search that uses the trendline command to plot a trendline. Or you could set up a dashboard panel that utilizes some tricksy implementation of chart overlay (pivot chart over trendline chart)...whatever works best for you.

mattness
Splunk Employee
Splunk Employee

That's an awesome solution to the problem. datamodel command FTW!

0 Karma

jeremiahc4
Builder

That makes sense then. I was able to use the datamodel command in order to take advantage of the information I already had organized there. a very simple example below;

| datamodel TicketData Ticket_Index search | search | timechart count | trendline sma2(count) as Trend

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...