Hello Splunkers!!
index=messagebus "AsrLocationStatusUpdate.AsrLocationStatus.LocationQualifiedName"="ASR/Hb/*/Entry*" OR "AsrLocationStatusUpdate.AsrLocationStatus.LocationQualifiedName"="ASR/Hb/*/Exit*" | stats count by "AsrLocationStatusUpdate.AsrLocationStatus.LocationQualifiedName"
|fields - _raw | fields AsrLocationStatusUpdate.AsrLocationStatus.LocationQualifiedName | rex field=AsrLocationStatusUpdate.AsrLocationStatus.LocationQualifiedName "(?<location>Aisle\d+)" | fields - AsrLocationStatusUpdate.AsrLocationStatus.LocationQualifiedName |strcat "raw" "," location group_name | stats count BY location group_name
Current visualisation I am getting by above search in column chart:
uagraw01_0-1701867042156.png
I want to obtain below visualization. Please guide me what changes I need to used in my current SPL to obtain below visualization.
uagraw01_1-1701867097228.png
Try changing
| stats count BY location group_nameto
| chart count BY location group_namethen use a stacked column chart
Below is the visualization I am getting after changing from stats to chart.
uagraw01_0-1701878820715.png
| timechart span=1d count by location
No results, I think strcat is working together with location and group_name
uagraw01_0-1701880475145.png
The visualisation you said you wanted doesn't have raw.location in. Please clarify what you want in your visualisation, what fields you have and how you want to use them
@ITWhisperer group_name is the raw.location and in the visualisation they are using. I want the same Visualisation as mentioned earlier.
| timechart span=1d count by group_name
@ITWhisperer Thats also not workng.
See the below events from the search and want the expected visualization.
uagraw01_0-1701883501939.png
I think you may have been told this before but if you want a time element in your visualisation, it needs to be in your results table. Your search is removing the _time field (or not including it). You need to rework your search accordingly.
I have included _time in my search, and the results are still the same.
uagraw01_0-1701884121587.png
Try this
| timechart span=1d count by location