Dashboards & Visualizations

how to draw a piechart which show the different msg got from splunk query

neha_h
Explorer

Hi,
I am getting below events from my splunk search but how to show them in pie chart.

Correlation Id :\"e7b4b14\", msg : Error is:[{\"code\":688,\"message\":\"api failed with error Invalid request".\"}]","podName":"test-service","category":"ERROR"}

Correlation Id :\"e7b4b14\", msg : Error is:[{\"code\":688,\"message\":\"api failed with error downsteam error".\"}]","podName":"test-service","category":"ERROR"}

basically I want to show the String which is there inside Error is array (basically the message part) in the pie chart for today's date

Tags (2)
0 Karma
1 Solution

to4kawa
SplunkTrust
SplunkTrust
| makeresults 
| eval _raw="raw
Correlation Id :\"e7b4b14\", msg : Error is:[{\"code\":688,\"message\":\"api failed with error Invalid request\".\"}]\",\"podName\":\"test-service\",\"category\":\"ERROR\"}
Correlation Id :\"e7b4b14\", msg : Error is:[{\"code\":688,\"message\":\"api failed with error downsteam error\".\"}]\",\"podName\":\"test-service\",\"category\":\"ERROR\"}"
| multikv forceheader=1
| rex "\[(?<codes>.*)\]"
| spath input=codes
| stats count by message

Viz >> Pie Chart

View solution in original post

0 Karma

to4kawa
SplunkTrust
SplunkTrust
| makeresults 
| eval _raw="raw
Correlation Id :\"e7b4b14\", msg : Error is:[{\"code\":688,\"message\":\"api failed with error Invalid request\".\"}]\",\"podName\":\"test-service\",\"category\":\"ERROR\"}
Correlation Id :\"e7b4b14\", msg : Error is:[{\"code\":688,\"message\":\"api failed with error downsteam error\".\"}]\",\"podName\":\"test-service\",\"category\":\"ERROR\"}"
| multikv forceheader=1
| rex "\[(?<codes>.*)\]"
| spath input=codes
| stats count by message

Viz >> Pie Chart

View solution in original post

0 Karma

neha_h
Explorer

Thank you @to4kawa ,
Can we group 1 type of error and it's count in 1 slice and other type and it's count in 2nd slice in pie chart?

0 Karma

to4kawa
SplunkTrust
SplunkTrust

yes, you can.

0 Karma

neha_h
Explorer

how can i do that?

0 Karma

neha_h
Explorer

Thanks, I could do that with | stats count by codes, Thank you so much @to4kawa

0 Karma

to4kawa
SplunkTrust
SplunkTrust

use eval to collect other types

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!