Splunk Search

Apply a trendline to a chart of Unique User Sessions span 30

JeffV
Explorer

I've got to be close. But having issues trying to figure out how to get a distinct count of user sessions to show up in a bar chart with a trendline. I'd like to see a distinct count of users for last year by month and have a trendline added.

<My Search>

| stats dc(userSesnId) as moving_avg
| timechart span=30d dc(userSesnId) as count_of_user_sessions | trendline sma4(moving_avg) as "Moving Average"
| rename count_of_user_sessions AS "Disctinct Count of User Sessions"
Labels (1)
0 Karma
1 Solution

JeffV
Explorer

Ended up going with this that works pretty good.

[My Search]
| timechart span=$span$d dc(userSesnId) as count_of_user_sessions | trendline sma$sma$(count_of_user_sessions) as "Moving Average"
| rename count_of_user_sessions AS "Disctinct Count of User Sessions"

View solution in original post

kiran_panchavat
Influencer

@JeffV 

kiran_panchavat_0-1736790374505.png

 

I hope this helps, if any reply helps you, you could add your upvote/karma points to that reply, thanks.

JeffV
Explorer

Hi Kiran, 

        Thanks for the info. I did post my solution earlier today. And, I think it pretty much mirrors what you've got.
So, at least I know I am on the right wavelength.

0 Karma

JeffV
Explorer

Ended up going with this that works pretty good.

[My Search]
| timechart span=$span$d dc(userSesnId) as count_of_user_sessions | trendline sma$sma$(count_of_user_sessions) as "Moving Average"
| rename count_of_user_sessions AS "Disctinct Count of User Sessions"

isoutamo
SplunkTrust
SplunkTrust

Hi

when you are using stats it removed all other fields.  Basically you have two options to do this. You should use timechart and also trendline or streamchat with window parameter.

r. Ismo

Get Updates on the Splunk Community!

Index This | How many sides does a circle have?

  March 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

New This Month - Splunk Observability updates and improvements for faster ...

What’s New? This month, we’re delivering several enhancements across Splunk Observability Cloud for faster and ...

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...