Splunk Search

Apply a trendline to a chart of Unique User Sessions span 30

JeffV
Explorer

I've got to be close. But having issues trying to figure out how to get a distinct count of user sessions to show up in a bar chart with a trendline. I'd like to see a distinct count of users for last year by month and have a trendline added.

<My Search>

| stats dc(userSesnId) as moving_avg
| timechart span=30d dc(userSesnId) as count_of_user_sessions | trendline sma4(moving_avg) as "Moving Average"
| rename count_of_user_sessions AS "Disctinct Count of User Sessions"
Labels (1)
0 Karma
1 Solution

JeffV
Explorer

Ended up going with this that works pretty good.

[My Search]
| timechart span=$span$d dc(userSesnId) as count_of_user_sessions | trendline sma$sma$(count_of_user_sessions) as "Moving Average"
| rename count_of_user_sessions AS "Disctinct Count of User Sessions"

View solution in original post

kiran_panchavat
SplunkTrust
SplunkTrust

@JeffV 

kiran_panchavat_0-1736790374505.png

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

JeffV
Explorer

Hi Kiran, 

        Thanks for the info. I did post my solution earlier today. And, I think it pretty much mirrors what you've got.
So, at least I know I am on the right wavelength.

0 Karma

JeffV
Explorer

Ended up going with this that works pretty good.

[My Search]
| timechart span=$span$d dc(userSesnId) as count_of_user_sessions | trendline sma$sma$(count_of_user_sessions) as "Moving Average"
| rename count_of_user_sessions AS "Disctinct Count of User Sessions"

isoutamo
SplunkTrust
SplunkTrust

Hi

when you are using stats it removed all other fields.  Basically you have two options to do this. You should use timechart and also trendline or streamchat with window parameter.

r. Ismo

Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...