Hello Splunk Family,
I am looking for help on making a graph in Splunk.
I am trying to monitor the amount of transactions by different methods names with different objects and separate that by date.
Here is an example of the data I have
The only thing is that there are a lot of Object Types and Object Names so maybe the top 10 object types per day.
Here is a lame attempt at a drawing of what I want.
Here is the code I got so far
[mycode] | bin _time span=1d| chart count(indexid) over actionelementname by actionelementtype
but it is missing the date and it is not stacked.
Any help would be deeply appreciated!
You can do
| eval c=actionelementtype.":".actionelementname
| chart sum(Total_Transactions) over _time by c
and then you will get it over time and you can stack it with the chart format options.
or how did you imaging visualising these two dimensions over _time?