Reporting

Report generation without using count

garima_chauhan
Path Finder

Hi,

I have a search which displays the last login made by a user on several hosts. I want to generate a report on this search but don't want to use count as the parameter. I am able to create the report by using count but it is meaningless to include count here. I have tried

| xyseries User Host LastLoginTime

but it also does not give me the desired output in the form of a graph. I want to display the User,Host and LastLogintime in the report.

How can I make the report meaningful without using count? I want the report to be a graph.
Please suggest.

Tags (2)
0 Karma

gfuente
Motivator

You can use the count search and then use

yoursearch| fields - count

regards

0 Karma

garima_chauhan
Path Finder

Hi,
removing count from search is not the problem. I am able to do that by using | table User Host LastLoginTime. My problem is that I want the report(graph) based on time without count being displayed in that.
Right now, when I generate a report on the search, it gives me user on one axis and count on another and the chart is blank since I have not used it with table.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...