Dashboards & Visualizations

How to make a timechart for a search?

acceo_purchasin
Explorer

Hi,
I have the following search and need to make a timechart of NoicerValues by APname. I tried this but there are not results.

index="ti-wifi" sourcetype=csv_wifi name=bsnMobileStationMacAddress
| rename values as MobileStationMacAddress
| join ip
   [search index="ti-wifi" name=bsnMobileStationRSSI
   | rename values as MobileStationRSSI ]
| join ip
   [search index="ti-wifi" name=bsnMobileStationSnr
   | rename values as MobileStationSnr]
| join ip
   [search index="ti-wifi" name=bsnMobileStationAPMacAddr
   | rename values as MacAddress ]
| lookup wifi.csv MacAddress OUTPUT APname
| eval MacAddress =APname
| eval totalCount = (MobileStationRSSI - MobileStationSnr)
| stats sum(totalCount) as totalNoice, count as Sessions by APname
| eval  NoiceFloor = round(totalNoice/Sessions,0)
| timechart list(NoiceFloor) by APname

Thank you

Ed

Tags (1)
0 Karma

pradeepkumarg
Influencer

list is not an appropriate function to use over timechart. Try avg or other mathematical aggregation functions

| timechart avg(NoiceFloor) by APname
0 Karma

acceo_purchasin
Explorer

Thank you for your answer, I already tried it but I received : Non result found.

Best regards

0 Karma

xpac
SplunkTrust
SplunkTrust

Can you show the results you get when you remove the last part of your search (the | timechart ...)?

0 Karma

acceo_purchasin
Explorer

I receive the following table :

APname totalNoice Sessions NoiceFloor
wap-3 -72 1 -72
wap-7 -755 8 -94

wap-8 -1081 11 -98
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

Best regards

0 Karma

xpac
SplunkTrust
SplunkTrust

At this point, your stats() has already removed all time information, so it's no longer possible to draw a timechart.
Do you actually want a time chart, that means the values for one or multiple series over a certain time frame? If yes, what time frame would that be?

0 Karma
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...