Dashboards & Visualizations

How to create a timechart for specific field value aggregations?

POR160893
Builder

Hi,

I am unable to create a timechart for specific field value aggregations. I have one field with 4 possible values. One timechart needs to be the total number across all 4 values and the second timechart meeds to be the total over 2 field values. The only thing on the legend should be TOTAL from the timechart.

Here is what my timechart and XML code currently looks like:
Cannot add totals on timecharts.PNG
And
Cannot add totals on timecharts - XML.PNG

Can you please help?

Thanks,

Patrick

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Remove the "by block_descrip" from both timechart commands

POR160893
Builder

Perfect, worked like a charm. 😃
Gave a Karma

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...