Dashboards & Visualizations

Stacked Bar Chart by the Number of Records per Category (stacked y-axis) by Week (x-axis)

tmaltizo
Path Finder

I'm trying to create a stacked chart with the following data:

y-axis: Number of Change Requests per Reason (stacked)
x-axis: by Week (format: 2017-01-23, 2017-01-30, n)

Result: The Number of Change Requests per Reason (stacked) by Week in the past 2 months

Search:
index=snow sourcetype="snow:change_request" reason="Firewall*"
| eval impDate= strptime(u_actual_impl_end_date, "%Y-%m-%d %H:%M:%S")
| where impDate>=relative_time(now(),"-2mon")
| dedup number

0 Karma

woodcock
Esteemed Legend

Maybe this:

index=snow sourcetype="snow:change_request" reason="Firewall*"
| eval _time = strptime(u_actual_impl_end_date, "%Y-%m-%d %H:%M:%S") 
| where _time >= relative_time(now(),"-2mon") 
| dedup number
| timechart span=1w count BY reason
0 Karma

adonio
Ultra Champion

Hi tmaltizo, do you have timestamps in your events?
if you do try this:

 index=snow sourcetype="snow:change_request" reason="Firewall*" | timechart span=7d count(reason)
usenull=f 

hope it helps

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...