Dashboards & Visualizations

How to make a linechart with a table and multiple lines

sjansma
Explorer

I want to make a presentation in a dashboard where I can see a line per service with the duration of each call of that service. 

I have made a table in splunk and would create a linechart wiht multiple lines (per service a line) with duration in y-as en time in x-as. How can i do that? Or is there another way to get that done?

my search:

index=test sourcetype=test-performance duration>0 | convert timeformat="%Y-%m-%dT%H:%M:%S%:z" ctime(_time) AS date | table date, metric, duration | sort by date

some events from the table. 

date                                                     metric        duration
2021-08-25T08:55:28+02:00 service1    93
2021-08-25T08:55:28+02:00 service1    4
2021-08-25T08:55:28+02:00 service3    3
2021-08-25T08:55:28+02:00 service4    1
2021-08-25T08:55:23+02:00 service5    84
2021-08-25T08:55:20+02:00 service5    88
2021-08-25T08:50:55+02:00 service1    91
2021-08-25T08:50:55+02:00 service1   18
2021-08-25T08:50:55+02:00 service3   14
2021-08-25T08:50:55+02:00 service6   2
2021-08-25T08:50:55+02:00 service7   4
2021-08-25T08:50:55+02:00 service4   5
2021-08-25T08:50:54+02:00 service8   46
2021-08-25T08:50:54+02:00 service9   43
2021-08-25T08:49:58+02:00 service1   88
2021-08-25T08:49:58+02:00 service1   17
2021-08-25T08:49:58+02:00 service3   16
2021-08-25T08:49:58+02:00 service10 10
2021-08-25T08:49:58+02:00 service11 10
2021-08-25T08:49:58+02:00 service6    2

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try

| xyseries _time metric duration
0 Karma

sjansma
Explorer

Found it. With "chart first(duration) OVER date BY metric" it has succeeded to create my dashboard

0 Karma
Get Updates on the Splunk Community!

Demo Day: Strengthen Your SOC with Splunk Enterprise Security 8.1

Today’s threat landscape is more complex than ever. Security operation centers (SOCs) are overwhelmed with ...

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...