Dashboards & Visualizations

How to modify timewrap legend?

Clovisa
Path Finder

Hi ! I am trying to modify the legend generated by the timewrap command. I saw that we could slightly change it with the parameter "series" but it's not really giving me what I want.

Let's say I want to have a sum of prices from this request :

index=sandbox earliest=-13d | timechart sum(prices) as "Sum of the prices" span=d | timewrap 1w series=relative

The legend will be Sum of the prices_1week_before and Sum of the prices_latest_week . I would like to have something like Sum of the prices for the week before and Sum of the prices for the latest week .

How can I get this ? Thanks !

0 Karma
1 Solution

niketn
Legend

One option would be to use series="exact" option to provide format for time series i.e.

<yourCurrentSearch>
| timewrap 1w series=exact time_format="Sum of the prices for %Y-%U week"

If you intend to use series="relative", you can use rename command to change series name as required (relative option will generate some generic names as per the series name in the timechart.

<yourCurrentSearch>
| timewrap 1w series=relative
| rename "Sum of the prices_latest_week" as  "Sum of the prices latest week",
         "Sum of the prices_1week_before" as  "Sum of the prices the week before",
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

niketn
Legend

One option would be to use series="exact" option to provide format for time series i.e.

<yourCurrentSearch>
| timewrap 1w series=exact time_format="Sum of the prices for %Y-%U week"

If you intend to use series="relative", you can use rename command to change series name as required (relative option will generate some generic names as per the series name in the timechart.

<yourCurrentSearch>
| timewrap 1w series=relative
| rename "Sum of the prices_latest_week" as  "Sum of the prices latest week",
         "Sum of the prices_1week_before" as  "Sum of the prices the week before",
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

Clovisa
Path Finder

That's perfect, thank you 😄

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...