Hi Everyone,
I have one requirement.
My query is like this
index="_internal" EventLogFiles
| eval DashboardName=if(like(uri, "%EventLogFiles%"), "EventLogFiles", "Unknown Dashboards")
| stats count by DashboardName user |append[search index="_internal" Extract
| eval DashboardName=if(like(uri, "%Extract%"), "Extract", "Unknown Dashboards")
| stats count by DashboardName user ]|sort -count
I am getting result like:
DashboradName User count
Extract ma 1
I want to display the three fields in Bar chart form.
Can someone guide me how can I do this.
Hi @aditsss
I want to display the three fields in Bar chart form// may we know what would be the 3rd field you want on the bar chart?
Some document references for the bar chart:
https://docs.splunk.com/Documentation/Splunk/8.0.6/Viz/ColumnBarCharts
PS - Karma points are appreciated, thanks!
The three fields are:
DashboardName ,User and count.
I want to display all three in bar chart but was not able to display.
Can someone guide me.