Splunk Search

Chart with multiple lines based on field values

fhobelman
Engager

case:

Logged events with differentiating fuellevel and the corresponding serial

Desired outcome:

alt text

So a graph with multiple lines, a line is based on a serialnumbers from the events, with vertically the value of a field within that same event.

Please help!

Tags (2)

DalJeanis
Legend

That's just a basic timechart.

your search that gets the events with _time serial and fuellevel
 | timechart max(fuellevel) as fuellevel by serial

You can also try max(), min(), avg() first() last(), or any other aggregate command that seems relevant.

fhobelman
Engager

Thanks! That indeed gives me the max fuellevel per day! What is the option if I want to see it per event? Because some serials will have like 10 events per day and others will just have a few or even none on a day.

0 Karma

akocak
Contributor

please send a sample of your data for better answer, however, I believe you are looking something similar to below:

 index=x sourcetype=y | eval number = fuellevel - correspondingserial | timechart values(number) values(serial1) values(serial2) 
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...