Dashboards & Visualizations

How to display three fields in a chart

aditsss
Builder

Hi Everyone,

I have one requirement.

My query is like this

index="_internal" EventLogFiles
| eval DashboardName=if(like(uri, "%EventLogFiles%"), "EventLogFiles", "Unknown Dashboards")
| stats count by DashboardName user |append[search index="_internal" Extract
| eval DashboardName=if(like(uri, "%Extract%"), "Extract", "Unknown Dashboards")
| stats count by DashboardName user ]|sort -count

I am getting result like:

DashboradName                                  User                         count

Extract                                                      ma                                   1

I want to display the three fields  in Bar chart form.

Can someone guide me how can I do this.

 

Labels (2)
0 Karma

inventsekar
Super Champion

Hi @aditsss 

I want to display the three fields  in Bar chart form// may we know what would be the 3rd field you want on the bar chart?

Some document references for the bar chart:

https://docs.splunk.com/Documentation/Splunk/8.0.6/Viz/ColumnBarCharts

 

PS - Karma points are appreciated, thanks!

0 Karma

aditsss
Builder

@inventsekar 

The three fields are:

DashboardName ,User and count.

I want to display all three in bar chart but was not able to display.

Can someone guide me.

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!