Dashboards & Visualizations

splunk dashboard chart(col) - how to display raw values

svec7186
Loves-to-Learn Lots

i added a column chart.  the metric values display as 1.  i published event with values at a given time

ex 

time 1 value 4

time 2 value 3

time 3 value 5

the x axis appears to display the time properly

how do i get the axis to display the raw values from the events?

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Please post the query you are using, but the last line of this query will give you a basic column chart showing the max of the values per time period

| makeresults
| eval x=split("4,3,5", ",")
| mvexpand x
| streamstats c
| eval _time=_time-(c*3600)
| timechart max(x)
0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...