Splunk Search

Apply a trendline to a chart of Unique User Sessions span 30

JeffV
Explorer

I've got to be close. But having issues trying to figure out how to get a distinct count of user sessions to show up in a bar chart with a trendline. I'd like to see a distinct count of users for last year by month and have a trendline added.

<My Search>

| stats dc(userSesnId) as moving_avg
| timechart span=30d dc(userSesnId) as count_of_user_sessions | trendline sma4(moving_avg) as "Moving Average"
| rename count_of_user_sessions AS "Disctinct Count of User Sessions"
Labels (1)
0 Karma
1 Solution

JeffV
Explorer

Ended up going with this that works pretty good.

[My Search]
| timechart span=$span$d dc(userSesnId) as count_of_user_sessions | trendline sma$sma$(count_of_user_sessions) as "Moving Average"
| rename count_of_user_sessions AS "Disctinct Count of User Sessions"

View solution in original post

kiran_panchavat
SplunkTrust
SplunkTrust

@JeffV 

kiran_panchavat_0-1736790374505.png

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

JeffV
Explorer

Hi Kiran, 

        Thanks for the info. I did post my solution earlier today. And, I think it pretty much mirrors what you've got.
So, at least I know I am on the right wavelength.

0 Karma

JeffV
Explorer

Ended up going with this that works pretty good.

[My Search]
| timechart span=$span$d dc(userSesnId) as count_of_user_sessions | trendline sma$sma$(count_of_user_sessions) as "Moving Average"
| rename count_of_user_sessions AS "Disctinct Count of User Sessions"

isoutamo
SplunkTrust
SplunkTrust

Hi

when you are using stats it removed all other fields.  Basically you have two options to do this. You should use timechart and also trendline or streamchat with window parameter.

r. Ismo

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...