Hi, I'm new to Splunk and I'm trying to create some visualizations on a Splunk dashboard using some CSV data. My data has the following columns:
{Id, SId, Timestamp, EId, Sev}.
I need to create a bar graph with timestamp on X-axis and Sev on the Y-axis. Any help regarding this?
Please use the below query,
| inputlookup myData.csv | eval _time=strftime(_time,"%m-%d-%Y %H:%M:%S.%Q") | timechart count by Sev
See if this gets you started. You'll need to replace with a time format string that matches the format of Timestamp. I've assumed 'Sev' is a numeric field. If it isn't then change 'max' to 'values'.
| inputlookup myData.csv | eval _time = strptime(Timestamp, "<format string>") | timechart max(Sev)
@richgalloway , I'm getting the following error on running the command:
Error in 'timechart' command: The specifier 'SEV' is invalid. It must be in form (). For example: max(size).
Looks like it only accepts a function like count or max for the timechart command.
Sorry about that. Answer is corrected.