Splunk Search

Accum statement

keyu921
Explorer

My data as following
Location|No.of active
US|200
UK|20
SZ|30

How to accum all those location by month by area chart
I now search as
w search as
|timechart span=1mon count by location| accum us as us| accum uk as uk | accum sz as sz | fields - uk us sz | fillnull

Tags (1)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@keyu921

Can you please more about your requirement and expected output?

0 Karma

keyu921
Explorer

bar chart that no.active and trend grow for last1yrs timechart span=1month

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...