Splunk Search

Chart with multiple lines based on field values

fhobelman
Engager

case:

Logged events with differentiating fuellevel and the corresponding serial

Desired outcome:

alt text

So a graph with multiple lines, a line is based on a serialnumbers from the events, with vertically the value of a field within that same event.

Please help!

Tags (2)

DalJeanis
Legend

That's just a basic timechart.

your search that gets the events with _time serial and fuellevel
 | timechart max(fuellevel) as fuellevel by serial

You can also try max(), min(), avg() first() last(), or any other aggregate command that seems relevant.

fhobelman
Engager

Thanks! That indeed gives me the max fuellevel per day! What is the option if I want to see it per event? Because some serials will have like 10 events per day and others will just have a few or even none on a day.

0 Karma

akocak
Contributor

please send a sample of your data for better answer, however, I believe you are looking something similar to below:

 index=x sourcetype=y | eval number = fuellevel - correspondingserial | timechart values(number) values(serial1) values(serial2) 
0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...