Splunk Enterprise

Display multiple values in multiple pie charts in trellis mode?

V21MGharib
Explorer

I would like to display multiple values in multiple pie charts.

For example: I want to display (Consumption & Remaining_Utilization) for each PowerStation in trellis mode

Using the following (partial) query

index="mtx" source="*Dual_Station*" MTX="*" PowerStation="*"
| eval Remaining_Utilization = Capacity - Consumption
| stats values(Remaining_Utilization) as Remaining_Utilization , values(Consumption) as Consumption by PowerStation

(What is missing after (stats)?
I checked each an every thread related to Pie charts in trellis mode in the community and couldn't find any answer

 

Hint: I use the following query to draw a single pie chart

index="mtx" source="*Dual_Station*" MTX="MTX_Name" PowerStation="PowerStation_Name"
| eval Remaining_Utilization = Capacity - Consumption
| chart values(Consumption) as Consumption over Remaining_Utilization
| transpose

 

 

Labels (2)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

Use this ending to the search

| stats values(Remaining_Utilization) as Remaining_Utilization , values(Consumption) as Consumption by PowerStation
| transpose 0 header_field=PowerStation column_name="Energy"
| stats values(*) AS * by Energy

I am not totally use why the final stats line makes it work, but it shows an extra trellis aggregation, but does not change the data format, i.e. there is a single trellis option without the stats, but two with that final stats.

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Use this ending to the search

| stats values(Remaining_Utilization) as Remaining_Utilization , values(Consumption) as Consumption by PowerStation
| transpose 0 header_field=PowerStation column_name="Energy"
| stats values(*) AS * by Energy

I am not totally use why the final stats line makes it work, but it shows an extra trellis aggregation, but does not change the data format, i.e. there is a single trellis option without the stats, but two with that final stats.

0 Karma

V21MGharib
Explorer

This works like magic, thank you! But, I still can't figure out what does this mean?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...