Hello everyone!
I have a log like this:
2018-11-29 09:33:41,758 Suspending endpoint : EPID1 - last suspend duration was : 30000ms and current suspend duration is : 30000ms - Next retry after : Thu Nov 29 09:34:11 CET 2018
2018-11-29 09:31:41,758 Suspending endpoint : EPID2 - last suspend duration was : 30000ms and current suspend duration is : 30000ms - Next retry after : Thu Nov 29 09:32:11 CET 2018
2018-11-29 09:31:11,758 Suspending endpoint : EPID1 - last suspend duration was : 30000ms and current suspend duration is : 30000ms - Next retry after : Thu Nov 29 09:31:41 CET 2018
2018-11-29 09:30:41,758 Suspending endpoint : EPID1 - last suspend duration was : 30000ms and current suspend duration is : 30000ms - Next retry after : Thu Nov 29 09:31:11 CET 2018
I'd like to make a chart with _time on the X-axis, and endpoints (EPID1, EPID2...) on the Y-axis, displaying a bar with the appropriate length for each suspension period.
I found [Gantt chart visualization] https://splunkbase.splunk.com/app/1741/ but I'm not allowed to install extra apps in my setup. Also found [this answer] https://answers.splunk.com/answers/82161/plot-up-or-down-state-over-time.html that seems quite appropriate but lacks flexibility as span times are hard coded in the query and I do not know beforehand which duration I have.
Suggestions?
Thanks in advance!