- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ttriman
Engager
01-06-2023
04:31 PM
Hello - I am trying to rename column produced using xyseries for splunk dashboard.
Can I do that or do I need to update our raw splunk log?
The log event details=
data: { [-]
errors: [ [+]
]
failed: false
failureStage: null
event: GeneratePDF
jobId: 144068b1-46d8-4e6f-b3a9-ead742641ffd
pageCount: 1
pdfSizeInMb: 7.250756
}
userId: user1@user.com
the current splunk query I have is -
| stats count by data.userId, data.failed | xyseries data.userId, data.failed count
Currently - my data is returning as follows
data.userId | false | true |
User1@user.com | 2 | |
User2@user.com | 3 | 1 |
User3@user.com | 2 | 2 |
Can I rename false = Successful and true = Failed?
Thank you in advance
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/00ea7/00ea728ddd59db76fcdafc5039051fc288625212" alt="richgalloway richgalloway"
richgalloway
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
SplunkTrust
01-06-2023
05:02 PM
Yes, you can rename the fields either before or after xyseries.
After:
| stats count by data.userId, data.failed
| xyseries data.userId, data.failed count
| rename false AS Successful, true AS Failed
Before:
| stats count by data.userId, data.failed
| eval data.failed = if(data.failed="false", "Successful", "Failed")
| xyseries data.userId, data.failed count
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ttriman
Engager
01-06-2023
05:04 PM
That works!! Thank you so much for the fast reply!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/00ea7/00ea728ddd59db76fcdafc5039051fc288625212" alt="richgalloway richgalloway"
richgalloway
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
SplunkTrust
01-06-2023
05:02 PM
Yes, you can rename the fields either before or after xyseries.
After:
| stats count by data.userId, data.failed
| xyseries data.userId, data.failed count
| rename false AS Successful, true AS Failed
Before:
| stats count by data.userId, data.failed
| eval data.failed = if(data.failed="false", "Successful", "Failed")
| xyseries data.userId, data.failed count
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
data:image/s3,"s3://crabby-images/63b2f/63b2fe586cbbf67f7ba1d1e6a80413550245b7cf" alt=""