Splunk Search

Creating Pivot Chart with two sums?

EricLloyd79
Builder

I am feeling more and more like the new Pivot UI functionality is way too limiting.
Can anyone help me to do a query like this:

sourcetype=xxx-prod (FOO OR BAR) | timechart span=30m sum(FOO) as foo sum(BAR) as bar

I know this seems like it would be an easy pivot to create. Simply auto-extract two fields, then press the + button the columns in the pivot table creation screen and add another column, creating a second columns of sums. Two columns of sums divided by time. The stats table looks great.

Then when I go to turn it into a bar graph, they force me to choose to identify my y-axis with only one sum. I explored the "Color" option and it won't allow me to include anything that is a sum, but rather straight up fields.

Please if anyone can help me understand that would be great. I'm trying to get together a presentation on the usefulness of data models and pivots for my company and I keep finding more reasons not to use it than reasons to use it.
Thanks.

0 Karma

okrabbe
Explorer

Unfortunately, you cannot do multiple aggregators in the pivot ui.

You could use the pivot command. ie.

| pivot datamodel  object sum(foo) AS "foo" sum(bar) AS "bar" SPLITROW _time AS _time PERIOD auto 

Obviously this kind of defeats the purpose of using pivot outside of the acceleration benefits but hopefully they will iterate over the interface and make it more useful.

EricLloyd79
Builder

Thank you for your answer. It clarified whether it is possible or not. Unfortunately, you are right, using the query itself defeating the purpose of getting the acceleration benefits and bypass the use of the pivot UI completely. I have a list of questions/concerns about the data models/pivot system they have in place that I am taking with me to Splunk conference.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...