Dashboards & Visualizations

Timechart multiple values per day

Path Finder

I have a dataset and looking for a timechart span=1d for the data I have from a location. 

| table _time Cases Hospitalizations ICO Recoveries Deaths

I want to display all these in one chart y exis over the past 7 days. 



Labels (1)
0 Karma


How about

| timechart span=1d sum(Cases) as Cases sum(Hospitalizations) as Hospitalizations sum(ICO) as ICO sum(Recoveries) as Recoveries sum(Deaths) as Deaths

However, there are 5 data elements above, but how many locations do you have and what granularity is _time in your source data, as sum() might not be the correct aggregation, e.g. if the value in your data reflects the latest value at that time, then max() would be correct.

but if you have a location split by then you will rapidly reach a number of series on the chart that will make it unreadable.

Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...