Splunk Search

Can I Rename the Variable on a Chart for Predict Command?

andrewkenth
Communicator

Just as it says..

Can I rename the variable on a chart for predict command? Instead of count and prediction(count) I'd like Actual and Estimated.

Thanks!

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust
0 Karma

martin_mueller
SplunkTrust
SplunkTrust
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

It should work inside the box as well, something like this:

... | timechart count as Actual | predict Actual as Estimated

That's basically a rename wrapped into the reporting command.

0 Karma

andrewkenth
Communicator

Not sure why I didn't think of this.. I was looking for an option in predict instead of thinking outside the box! This works:

| rename count as Actual | rename prediction(count) as Estimated

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...