I'm fairly inexperienced with writing complex charting XML in Splunk, and I'd like to see if anyone has an example for how to use RatioBar graphs. I'd like to create a graph of the count of all events over time, with the bars splitting out into the ratio of which hosts they came from (perhaps limiting to the top 5 or something). Thanks in advance
The easiest way to do this is in the advanced charting view.
Search app >> views >> advanced charting
... | timechart count by <field> limit=5 useother=f
Set chart type to "column" and stack mode to "stacked" or "100% stacked" if you prefer.
The easiest way to do this is in the advanced charting view.
Search app >> views >> advanced charting
... | timechart count by <field> limit=5 useother=f
Set chart type to "column" and stack mode to "stacked" or "100% stacked" if you prefer.
Excellent! Thanks