Reporting

Report generation without using count

garima_chauhan
Path Finder

Hi,

I have a search which displays the last login made by a user on several hosts. I want to generate a report on this search but don't want to use count as the parameter. I am able to create the report by using count but it is meaningless to include count here. I have tried

| xyseries User Host LastLoginTime

but it also does not give me the desired output in the form of a graph. I want to display the User,Host and LastLogintime in the report.

How can I make the report meaningful without using count? I want the report to be a graph.
Please suggest.

Tags (2)
0 Karma

gfuente
Motivator

You can use the count search and then use

yoursearch| fields - count

regards

0 Karma

garima_chauhan
Path Finder

Hi,
removing count from search is not the problem. I am able to do that by using | table User Host LastLoginTime. My problem is that I want the report(graph) based on time without count being displayed in that.
Right now, when I generate a report on the search, it gives me user on one axis and count on another and the chart is blank since I have not used it with table.

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...