Splunk Search

Chart for Events falling within same time

manuarora12
New Member

I have events
event_starttime, event_endtime, event_duration, event_name

I want chart of events falling in common time

Tags (2)
0 Karma

manuarora12
New Member

Event_StartTime="2018-06-07 08:31:10" Event_EndTime="2018-06-07 08:31:38" Event_Duration="0 00:00:28" Event_Name="Process A"
Event_StartTime="2018-06-07 07:59:02" Event_EndTime="2018-06-07 09:34:21" Event_Duration="0 01:35:19" Event_Name="Process B"

Event_StartTime="2018-06-07 09:31:10" Event_EndTime="2018-06-07 09:31:38" Event_Duration="0 00:00:28" Event_Name="Process A"

Now you can see in window 07:59 - 09:34: 3Process were running.

I want chart like below
09:00 - 12:00 - Process running and name and count of process.
12:00 -3:00
3:00 - 6:00 and so on

0 Karma

niketnilay
Legend

@manuarora12 check out Timeline Custom Visualization

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

adonio
SplunkTrust
SplunkTrust

please elaborate, please share some more details and sample data.
we want to help

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!