Dashboards & Visualizations

How do I plot a trendline on a pivot chart

jeremiahc4
Builder

I am using Pivot to create a dashboard full of pretty charts. Some of these charts lend themselves to having a trendline drawn on them. However, I can't seem to plot a trendline in Pivot. Am I missing something obvious or is this an advanced scenario where I need to bust out the command reference and do it via normal search means?

0 Karma
1 Solution

mattness
Splunk Employee
Splunk Employee

Trendlines aren't available for the initial release of Pivot. You can use Pivot in conjunction with the old-school method of adding trendlines to charts by getting the pivot search string...

  • create your pretty chart in Pivot
  • add it to a dashboard
  • click Edit > Edit Panel and then click the pivot symbol and select Edit Search String. This reveals a simplified version of the pivot search that uses the pivot command. Eventually you may become familiar enough with the pivot command to code searches using it.

...and then using that search string in a larger search that uses the trendline command to plot a trendline. Or you could set up a dashboard panel that utilizes some tricksy implementation of chart overlay (pivot chart over trendline chart)...whatever works best for you.

View solution in original post

mattness
Splunk Employee
Splunk Employee

Trendlines aren't available for the initial release of Pivot. You can use Pivot in conjunction with the old-school method of adding trendlines to charts by getting the pivot search string...

  • create your pretty chart in Pivot
  • add it to a dashboard
  • click Edit > Edit Panel and then click the pivot symbol and select Edit Search String. This reveals a simplified version of the pivot search that uses the pivot command. Eventually you may become familiar enough with the pivot command to code searches using it.

...and then using that search string in a larger search that uses the trendline command to plot a trendline. Or you could set up a dashboard panel that utilizes some tricksy implementation of chart overlay (pivot chart over trendline chart)...whatever works best for you.

mattness
Splunk Employee
Splunk Employee

That's an awesome solution to the problem. datamodel command FTW!

0 Karma

jeremiahc4
Builder

That makes sense then. I was able to use the datamodel command in order to take advantage of the information I already had organized there. a very simple example below;

| datamodel TicketData Ticket_Index search | search | timechart count | trendline sma2(count) as Trend

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...