Splunk Dev

Can anyone tell how to get below graph using splunk.

sxp5686
Explorer

I want two y-axis graph having percentage on left side and number (in thousands) on right side.And on x axis we should have total no. of cases on each day.

Tags (1)
0 Karma
1 Solution

cmerriman
Super Champion

Do you have th syntax worked out for number of cases, percentage and the other number?
If so, in the format option, there is a chart overlay button, click in that and choose the number field so that it displays on the right.
https://docs.splunk.com/Documentation/Splunk/7.0.1/SearchTutorial/Chartoverlays
If you don’t have the syntax worked out, if you could share some sample data, that could be helpful.

View solution in original post

naidusadanala
Communicator

There is an app splunk 6.x examples which provides basic concepts and also sample searches to populate dashboards fast and easily.

Hopefully it helps

https://splunkbase.splunk.com/app/1603/

cmerriman
Super Champion

Do you have th syntax worked out for number of cases, percentage and the other number?
If so, in the format option, there is a chart overlay button, click in that and choose the number field so that it displays on the right.
https://docs.splunk.com/Documentation/Splunk/7.0.1/SearchTutorial/Chartoverlays
If you don’t have the syntax worked out, if you could share some sample data, that could be helpful.

sxp5686
Explorer

Sorry but I do not have source code for this but take it like you are having two fields at the end of the search.
By using only that two fields you have to make the graph.

0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...