Splunk Search

Creating Bubble Chart with both X and Y axis as a category, and bubble size as a metric

ferenc0521
New Member
| makeresults 
| eval A=" North|WidgetA|1000###
 South|WidgetA|2000###
 East|WidgetA|1000###
 West|WidgetA|300###
North|WidgetB|200###
 South|WidgetC|20###
 East|WidgetC|150###
 West|WidgetB|300###" 
| makemv delim="###" A 
 | mvexpand A 
 | rex field=A "^(?<Region>[^|]+)\|(?<Widget>[^|]+)\|(?<Sales>[^|]+)"
 | stats  sum(Sales) as Sales by Widget,Region
 | table Widget, Region,Sales

Creates a table with unique widget, region pairs as rows, sum(sales) as a metric.
Expected X axis with widget names (WidgetA, WidgetB, WidgetC), Y axis as region names (North, South, East, West), bubble size as sum(Sales).
Observed all the bubbles at 0,0 and both X and Y axis is numeric.

One other answer suggested adding

        <option name="charting.axisX">category</option>
        <option name="charting.axisY">category</option>

Would specify the non-numeric option, but didn't work for me.

The few answers for Bubble (I guess Scatter will be the same) was from way back, tried them but didn't work.
In desperation I tried

        <option name="charting.axisX">Widget</option>
        <option name="charting.axisY">Region</option>

too, but to no avail...

Tags (4)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...