Dashboards & Visualizations

How to chart with 2 different data over a time period?

angersleek
Path Finder
index=my-index ns=my-namespace app_name=my-api DECISION IN (YES, NO) | chart list(DECISION) BY PRODUCT_ID

For above query, how could I possibly chart it for a query of 90 days. I want the data to be shown weekly. There are 11 possible ids for the value PRODUCT_ID.

Thus total 3 things to consider. PRODUCT_ID (11 types), DECISION (2 types) and the timeline to be shown weekly for a 90 day period.
How can I chart this in Splunk? Bit confused as to what chart would fit this scenario and how to write the query to chart this. Appreciate any advice. Thanks.

Tags (1)
0 Karma
1 Solution

to4kawa
Ultra Champion
index=my-index ns=my-namespace app_name=my-api DECISION IN (YES, NO)

| fields _time DECISION PRODUCT_ID
| bin span=1d _time
| stats  values(PRODUCT_ID) as PRODUCT_ID by _time DECISION

as you like.

View solution in original post

to4kawa
Ultra Champion
index=my-index ns=my-namespace app_name=my-api DECISION IN (YES, NO)

| fields _time DECISION PRODUCT_ID
| bin span=1d _time
| stats  values(PRODUCT_ID) as PRODUCT_ID by _time DECISION

as you like.

skoelpin
SplunkTrust
SplunkTrust

Try this

index=my-index ns=my-namespace app_name=my-api DECISION IN (YES, NO) earliest=-90d@d latest=now
| timechart values(DECISION) BY PRODUCT_ID
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...