I finally got my splunk search to work but it only returns 10 of the 140 tests that are in the database. The trellis bell curve plots (bar chart) are arranged by test name but I only get 10 plots. What could possibly be wrong??
This works
sourcetype=mfgtestengsoftware | search "Result Logged" "Results{}.Pass"=true "B1611" "CCS" | spath Results{}.Name | rename Results{}.Name AS StepName | spath Results{}.Actual | rename Results{}.Actual AS Actual | eval Actual = Round(Actual) | transaction StepName, Actual | bin Actual span=10 | chart count over Actual by StepName useother=f
There is now a JIRA on this ( SPL-176965
). Supposedly all this will be fixed in the Dashboards (Beta)
app first, when they roll trellis
into it:
https://splunkbase.splunk.com/app/4710/
@Lynyrd - if your issue has been resolved, please accept that answer that solved it, so the question will show as closed. Thanks!
@Lynyrd, issue is not with Trellis, it is with chart
command which returns only 10 results by default. Add limit=0
<YourCurrentSearch>
| chart count over Actual by StepName limit=0 useother=f
PS: I feel your search query would need a lot of optimization. If you have query performance issues, do post it with code button 101010
on Splunk Answers so that special characters do not escape.
All of my plots have the same Y axis value, how can I adjust the X and Y axis dimensions so that each graphic is unique?
I think you are looking for Trellis Layout option to use Independent
scale instead of Shared
.
<option name="trellis.scales.shared">0</option>
You can check out Trellis Layout related documentation on Splunk Docs: http://docs.splunk.com/Documentation/Splunk/latest/Viz/VisualizationTrellis
@Lynyrd stumbled upon this old post. If your issue is resolved kindly accept the answer and up vote the answer/comment that helped.
Thank you. This appears to work nicely. I will move forward and if I get into any trouble I'll post another question. Thanks again for the help... PS I Bought a book "Exploring SPLUNK" Primer and Cook book and it does help but does not fully explain all aspects.
@Lynyrd, best place to start is Splunk Search Fundamentals 1
elearning course on Splunk Education. Complete Splunk Documentation online is available on docs.splunk.com and dev.splunk.com has walk-through and examples.
Following is a good place to refer to Splunk Search Optimization: http://docs.splunk.com/Documentation/Splunk/latest/Search/Quicktipsforoptimization
If your issue is resolved, please accept the answer and up vote comments that helped.