Dashboards & Visualizations

How to obtain a visualisation based on time (x-axis) for a multi series search (table)?

zebu14
Explorer

Hello,

I am using a table type search with visualisation with multiple fields to render.
The purpose of this search is to match two events in a transaction (incoming file and outgoing file) and calculate some infos (bandwidth, duration...)

My search is :

index="" sourcetype= | transaction file_component maxpause=5m |eval debit=Size/duration | table file_component,Size,duration,debit

This give me a multi series visualisation in which "file_component" (the transaction id) is the x-axis, so events are sorted with transaction id but not with time.

I tried to add:

index="" sourcetype= | transaction file_component maxpause=5m |eval debit=Size/duration | table file_component,Size,duration,debit,_time | sort by _time

This worked for sorting the results by time, but X-axis is still based on transaction id and I can't find the date and time of a transfer by just hovering the mouse on the graphs.

alt text

Any idea?

Thanks

0 Karma
1 Solution

renjith_nair
Legend

Hi @zebu14,

You could get _time on x-axis by changing the order ie. index="" sourcetype= | transaction file_component maxpause=5m |eval debit=Size/duration | table _time ,file_component,Size,duration,debit
However, normally time based charting is done based on aggregation function using stats/timechart

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

renjith_nair
Legend

Hi @zebu14,

You could get _time on x-axis by changing the order ie. index="" sourcetype= | transaction file_component maxpause=5m |eval debit=Size/duration | table _time ,file_component,Size,duration,debit
However, normally time based charting is done based on aggregation function using stats/timechart

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

zebu14
Explorer

Thanks for the tip.
I usually use timechart function, but I'm still a beginner and I still don't manage the use of timechart with multiple parameters

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...