Dashboards & Visualizations

want to combine time chart and table

oda
Communicator

I want to use timechart as instead of sparkline.

It is the current search sentence.

index=test | table A B C D | join A [ search index=test |

chart sparkline(max(B)) by A ] | makemv delim="," setsv=true sparkline(max(A))

Do you have any suggestions?

Thanks.
alt text

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Add _time to your table.

0 Karma

oda
Communicator

Thank you for answering. But,I would like to have a way like tableau.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Can you share a link or a screenshot of what you mean?

0 Karma

oda
Communicator

Thank you for contacting.
Could you check it because I added a screenshot?

0 Karma

jkat54
SplunkTrust
SplunkTrust
Try this

index=test |timechart max(A) max(B) max(C) max(D)
0 Karma

oda
Communicator

I appreciate your suggestion.
It is displayed in one figure, it is easy to see, but this time I want to display it separately.

For example, every host.

0 Karma

niketn
Legend

Do you want help with post Processing to run single base search for table and timechart? While displaying can you display timechart on click of a particular table row? If yes please check out Table Row Expansion (More Details) and In-Page Drilldown with Perma-linking examples in Splunk 6.x Dashboard Examples app

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

oda
Communicator

Thank you. I am glad your reply.However, I made that setting.It can display only one graph.I would like to have a way like tableau.Best regards.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...