Dashboards & Visualizations

Unable to Chart Numeric Fields from Single Event

Joshua
Explorer

I've been really struggling with what seemed at first very simple is proving impossible, any help on this would be great.

I have a one event which is extracting three numerical values which I want correlated within a Pie chart. However no matter the reporting format I choose it will only ever display one value in the charts i.e. due to being only one event.

Event Example

<Report timestamp="2011-04-20 03:31:12.035">
    <Status count="54" name="RUNNING"/>
    <Status count="53" name="NOTDEPLOYED"/>
    <Status count="1" name="UNKNOWN"/>
  </Report>

I then have field extractions in my props.conf to give me the values from each count so if I was too search "sourcetype="TIBCO_EMS_SAF" | table, RunningCount, NotDeployedCount, UNKNOWN"

RunningCount = 54
NotDeployedCount = 53
UNKNOWN = 1

So all I need is those fields/values from a single event in a Pie Chart against each other.

Any suggestions would be great.

Thanks,

Joshua

Tags (2)
1 Solution

Ayn
Legend

Use transpose:

sourcetype="TIBCO_EMS_SAF" 
| table RunningCount, NotDeployedCount, UNKNOWN
| transpose

This transposes the table so that each field gets its own row, which you can then use as source data for your pie chart.

View solution in original post

Ayn
Legend

Use transpose:

sourcetype="TIBCO_EMS_SAF" 
| table RunningCount, NotDeployedCount, UNKNOWN
| transpose

This transposes the table so that each field gets its own row, which you can then use as source data for your pie chart.

Joshua
Explorer

This worked thanks!

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...