Dashboards & Visualizations

Plot service unavailability over time

danielec
Engager

Hello everyone!

I have a log like this:
2018-11-29 09:33:41,758 Suspending endpoint : EPID1 - last suspend duration was : 30000ms and current suspend duration is : 30000ms - Next retry after : Thu Nov 29 09:34:11 CET 2018
2018-11-29 09:31:41,758 Suspending endpoint : EPID2 - last suspend duration was : 30000ms and current suspend duration is : 30000ms - Next retry after : Thu Nov 29 09:32:11 CET 2018
2018-11-29 09:31:11,758 Suspending endpoint : EPID1 - last suspend duration was : 30000ms and current suspend duration is : 30000ms - Next retry after : Thu Nov 29 09:31:41 CET 2018
2018-11-29 09:30:41,758 Suspending endpoint : EPID1 - last suspend duration was : 30000ms and current suspend duration is : 30000ms - Next retry after : Thu Nov 29 09:31:11 CET 2018

I'd like to make a chart with _time on the X-axis, and endpoints (EPID1, EPID2...) on the Y-axis, displaying a bar with the appropriate length for each suspension period.

I found [Gantt chart visualization] https://splunkbase.splunk.com/app/1741/ but I'm not allowed to install extra apps in my setup. Also found [this answer] https://answers.splunk.com/answers/82161/plot-up-or-down-state-over-time.html that seems quite appropriate but lacks flexibility as span times are hard coded in the query and I do not know beforehand which duration I have.

Suggestions?

Thanks in advance!

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...