Dashboards & Visualizations

How to "fill in" transaction gaps in timeline

spamphile
Engager

I'm trying to create a visualization of web service activity. I thought the timeline would be a good representation of when services are up and down. Unfortunately, the logs I have to work with ping services every 15 minutes. So every 15 minutes, there's a log that states: <serviceName> is up: true OR <serviceName> is up:false

I was able to implement this query and get something back (last 60 minutes):

index=application_activity up | transaction startswith="*true" endswith="*false" by service | table _time service duration

Screen Shot 2020-06-05 at 4.39.28 PM.png

But of course because of the 15 minute time interval, it has huge gaps. How can I have these gaps filled in as long it as true the service is up, and only have gaps show when it is false? I'm also open to another recommendation for a visualization.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...