Dashboards & Visualizations

Timechart for addtotals value

thomas6m
New Member

Hi Team,
I am trying to create timechart addtotals value. But when I using the query, I am getting Total, others and few more lines. Please let me know how to suppress/hide all line other than addtotals (Total) value.

index=int_gcg_apac_pcf_application_dm_169688 OR index=int_gcg_apac_pcf_foundation_dm_169688 cf_org_name=* cf_space_name=* cf_app_name=* instance_index=*|bucket _time span=1m| dedup _time cf_org_name cf_space_name cf_app_name instance_index| fields _time cf_org_name cf_space_name cf_app_name instance_index|timechart span=1m count(instance_index) by cf_app_name | addtotals

Regards,
Tom

Labels (1)
Tags (1)
0 Karma
1 Solution

to4kawa
Ultra Champion
....
| fields _time Total

View solution in original post

0 Karma

thomas6m
New Member

thanks you so much. It worked. \

0 Karma

to4kawa
Ultra Champion
....
| fields _time Total
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...