Splunk Cloud Platform

Custom Pie Chart

saibal6
Path Finder

I have  a requirement where I have to show a pie chart which shows pending/opened/assigned service request from last Feb to till now but the time span should be 40, as well as which services are older than 80 days. it will come in ">80" legend. Like in this way only (0-40, 40-80, >80)

 

My Search query is : 

index a
| table a b c d        [a b c d stands for a=user, b=date, c=service request number and d=days]
| chart count(c) by d span=40  

 

My Output :

days                 count(number)
0-40                          3111
40-80                       2252
80-120                      478
120-160                 2757


But I want my output in manner :
days                 count(number)
0-40                          3111
40-80                       2252
>80                           3235 (478+2757)

 

Is it possible to get my desired output in the pie chart?

Please give me an example with a search query if we can do that. 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...