Hi Splunk Community,
I was wondering if it was possible to have a chart that was made up from 3 fields....
I have already built a chart that has columns for each Account where each column is stacked with the Action --> | chart count by Account, Action
Can i break down into days using the _time field, so it counts by days?
Example of data:
_time | Account | Action |
2021-10-20 10:04:03.778 | account1 | Delete |
2021-10-21 11:04:03.778 | account2 | Write |
2021-10-21 11:05:03.778 | account1 | Write |
Thanks You,
Zoe
Hi @zoebanning ,
If this helps, give a thumbs-up 🙂
Happy Splunking!!
Hi @zoebanning ,
If this helps, give a thumbs-up 🙂
Happy Splunking!!
Regarding the chart. Is there a possibility to hide or remove a column in the column chart based on nullvalue. (The space created visually) ? As of now it is created spaces to 3 bars, thus its only displaying the value of given instance.