Dashboards & Visualizations

Time chart on object property

larryluckland
Engager

I'm new to Splunk and I'm trying to do something that is probably basic but I haven't been able to figure out how to do it.

 

I have a log in Splunk which contains an http_query along the lines of:

```

my_object[prop1]=someVal&my_object[prop2]=someOtherVal

```

I'm trying to use a timechart to inspect these values. I've tried:
`timechart count by my_object[prop1]` which tells me prop1 is undefined.


Then also tried

`timechart count by my_object.prop1`  which gives me a time series with NULL everywhere.

How can I do this?

Labels (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Run a basic search (without timechart) in "Smart Mode" and see what fields are being extracted by Splunk (field sidebar appears on left on "Events" tab). If your http_query fields are extracted, then use the exact name in timechart as they appear in field sidebar.

View solution in original post

somesoni2
Revered Legend

Run a basic search (without timechart) in "Smart Mode" and see what fields are being extracted by Splunk (field sidebar appears on left on "Events" tab). If your http_query fields are extracted, then use the exact name in timechart as they appear in field sidebar.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...