Splunk Search

Creating Pivot Chart with two sums?

EricLloyd79
Builder

I am feeling more and more like the new Pivot UI functionality is way too limiting.
Can anyone help me to do a query like this:

sourcetype=xxx-prod (FOO OR BAR) | timechart span=30m sum(FOO) as foo sum(BAR) as bar

I know this seems like it would be an easy pivot to create. Simply auto-extract two fields, then press the + button the columns in the pivot table creation screen and add another column, creating a second columns of sums. Two columns of sums divided by time. The stats table looks great.

Then when I go to turn it into a bar graph, they force me to choose to identify my y-axis with only one sum. I explored the "Color" option and it won't allow me to include anything that is a sum, but rather straight up fields.

Please if anyone can help me understand that would be great. I'm trying to get together a presentation on the usefulness of data models and pivots for my company and I keep finding more reasons not to use it than reasons to use it.
Thanks.

0 Karma

okrabbe
Explorer

Unfortunately, you cannot do multiple aggregators in the pivot ui.

You could use the pivot command. ie.

| pivot datamodel  object sum(foo) AS "foo" sum(bar) AS "bar" SPLITROW _time AS _time PERIOD auto 

Obviously this kind of defeats the purpose of using pivot outside of the acceleration benefits but hopefully they will iterate over the interface and make it more useful.

EricLloyd79
Builder

Thank you for your answer. It clarified whether it is possible or not. Unfortunately, you are right, using the query itself defeating the purpose of getting the acceleration benefits and bypass the use of the pivot UI completely. I have a list of questions/concerns about the data models/pivot system they have in place that I am taking with me to Splunk conference.

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...