Dashboards & Visualizations

Timechart multiple values per day

jenkinsta
Path Finder

I have a dataset and looking for a timechart span=1d for the data I have from a location. 

| table _time Cases Hospitalizations ICO Recoveries Deaths

I want to display all these in one chart y exis over the past 7 days. 

 

 

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

How about

| timechart span=1d sum(Cases) as Cases sum(Hospitalizations) as Hospitalizations sum(ICO) as ICO sum(Recoveries) as Recoveries sum(Deaths) as Deaths

However, there are 5 data elements above, but how many locations do you have and what granularity is _time in your source data, as sum() might not be the correct aggregation, e.g. if the value in your data reflects the latest value at that time, then max() would be correct.

but if you have a location split by then you will rapidly reach a number of series on the chart that will make it unreadable.

Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...