Splunk Enterprise

Display multiple values in multiple pie charts in trellis mode?

V21MGharib
Explorer

I would like to display multiple values in multiple pie charts.

For example: I want to display (Consumption & Remaining_Utilization) for each PowerStation in trellis mode

Using the following (partial) query

index="mtx" source="*Dual_Station*" MTX="*" PowerStation="*"
| eval Remaining_Utilization = Capacity - Consumption
| stats values(Remaining_Utilization) as Remaining_Utilization , values(Consumption) as Consumption by PowerStation

(What is missing after (stats)?
I checked each an every thread related to Pie charts in trellis mode in the community and couldn't find any answer

 

Hint: I use the following query to draw a single pie chart

index="mtx" source="*Dual_Station*" MTX="MTX_Name" PowerStation="PowerStation_Name"
| eval Remaining_Utilization = Capacity - Consumption
| chart values(Consumption) as Consumption over Remaining_Utilization
| transpose

 

 

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

Use this ending to the search

| stats values(Remaining_Utilization) as Remaining_Utilization , values(Consumption) as Consumption by PowerStation
| transpose 0 header_field=PowerStation column_name="Energy"
| stats values(*) AS * by Energy

I am not totally use why the final stats line makes it work, but it shows an extra trellis aggregation, but does not change the data format, i.e. there is a single trellis option without the stats, but two with that final stats.

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Use this ending to the search

| stats values(Remaining_Utilization) as Remaining_Utilization , values(Consumption) as Consumption by PowerStation
| transpose 0 header_field=PowerStation column_name="Energy"
| stats values(*) AS * by Energy

I am not totally use why the final stats line makes it work, but it shows an extra trellis aggregation, but does not change the data format, i.e. there is a single trellis option without the stats, but two with that final stats.

0 Karma

V21MGharib
Explorer

This works like magic, thank you! But, I still can't figure out what does this mean?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2025 SplunkTrust is officially open! If you ...

Splunk Answers Content Calendar, June Edition II

Get ready to dive into Splunk Dashboard panels this week! We'll be tackling common questions around ...

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...