Dashboards & Visualizations

How to create stackedbar chart on time series

kwsk_t2y
Explorer

I want to know how to create(search) stacked bar chart like this.

|<-----PC ON---->|<-----PC Standby------>|<----PC ON--->|<-------- PC shutdown(no log)------>|<-----PC ON---->|
x|-9:00 -------------------------------------------------------------------------------------------------------------------------------------

alt text

data format are follows.
ex)
start,end,state,duration
9:00:00,9:30:00,ON,00:30:00
9:30:00,9:45:00.Standby,00:15:00
9:45:00,10:15:00,ON,00:30:00
...

Tags (1)
0 Karma
1 Solution

niketn
Legend

@kwsk_t2y, please check out Timeline Custom Visualization on Splunkbase: https://splunkbase.splunk.com/app/3120/

Documentation can be found at : https://docs.splunk.com/Documentation/Timeline/latest/TimelineViz/TimelineIntro

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

niketn
Legend

@kwsk_t2y, please check out Timeline Custom Visualization on Splunkbase: https://splunkbase.splunk.com/app/3120/

Documentation can be found at : https://docs.splunk.com/Documentation/Timeline/latest/TimelineViz/TimelineIntro

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

kwsk_t2y
Explorer

Thank you for your information.
I'll try it!

0 Karma

niketn
Legend

@kwsk_t2y, please check and confirm. I will convert to answer if this suits your need, so that you can accept and mark the question answered.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

kwsk_t2y
Explorer

I could do my needs. thank you very much.

0 Karma

niketn
Legend

@kwsk_t2y,glad it worked. Please accept the answer.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...