Dashboards & Visualizations

Pie chart help

Marco
Communicator

Hi Splunkers,

I am currently trying to create a pie chart that gets its data from a token:

host=* | eval $Overview$ | chart sum(Warning) as "Warnings"  sum(Violation)  as  Violations sum(Alerts) as Alerts  over sum(ALL)

I am looking to create a pie chart that shows these three values. Any help is appreciated 

 

Thank you,

Marco

Labels (4)
0 Karma
1 Solution

Marco
Communicator

Hi Splunkers,

I found the solution:

host=* | eval $Overview$ | chart sum(Warning) as "Warnings"  sum(Violation)  as  Violations sum(Alerts) as Alerts | transpose

 

I was missing the transpose command.

Thank you,

Marco 

View solution in original post

0 Karma

Marco
Communicator

Hi Splunkers,

I found the solution:

host=* | eval $Overview$ | chart sum(Warning) as "Warnings"  sum(Violation)  as  Violations sum(Alerts) as Alerts | transpose

 

I was missing the transpose command.

Thank you,

Marco 

0 Karma

to4kawa
Ultra Champion

sample:

| makeresults count=20
| eval Warning = random() %  20,Violation = random() % 20, Alerts = random() % 20
| rename COMMENT as "The sample. from here, the logic."
| chart sum(Warning) as "Warnings"  sum(Violation)  as  Violations sum(Alerts) as Alerts
| eval tmp="1"
| untable tmp Status Count
| fields - tmp
| rename COMMENT as "Viz >> Pie Chart"
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...