Splunk Search

Conditionally Omit Bin from Chart

rpecka
Explorer

Hi, I’m trying to make a stacked bar chart visualization where my y axis is milliseconds, my x axis is a task ID, and I’m splitting by a stage ID. My query is:

| chart max("duration") over task_id by "stage_id" | table task_id, stage_1, stage_2, stage_3, *

In my results, tasks where stage 1 occurred are so long that they make all the other bars look really tiny. Is there a way that I could add to my query to filter out the task_ids where stage_1 occurred?

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

You could add a where clause to remove rows where stage_1 values is null or =0

| where isnull(stage_1) OR stage_1=0

or you could make the y-axis log scale, which would reduce the impact of the stage_1 values if that works for you.

 

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

You could add a where clause to remove rows where stage_1 values is null or =0

| where isnull(stage_1) OR stage_1=0

or you could make the y-axis log scale, which would reduce the impact of the stage_1 values if that works for you.

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...