Splunk Search

Creating Pivot Chart with two sums?

EricLloyd79
Builder

I am feeling more and more like the new Pivot UI functionality is way too limiting.
Can anyone help me to do a query like this:

sourcetype=xxx-prod (FOO OR BAR) | timechart span=30m sum(FOO) as foo sum(BAR) as bar

I know this seems like it would be an easy pivot to create. Simply auto-extract two fields, then press the + button the columns in the pivot table creation screen and add another column, creating a second columns of sums. Two columns of sums divided by time. The stats table looks great.

Then when I go to turn it into a bar graph, they force me to choose to identify my y-axis with only one sum. I explored the "Color" option and it won't allow me to include anything that is a sum, but rather straight up fields.

Please if anyone can help me understand that would be great. I'm trying to get together a presentation on the usefulness of data models and pivots for my company and I keep finding more reasons not to use it than reasons to use it.
Thanks.

0 Karma

okrabbe
Explorer

Unfortunately, you cannot do multiple aggregators in the pivot ui.

You could use the pivot command. ie.

| pivot datamodel  object sum(foo) AS "foo" sum(bar) AS "bar" SPLITROW _time AS _time PERIOD auto 

Obviously this kind of defeats the purpose of using pivot outside of the acceleration benefits but hopefully they will iterate over the interface and make it more useful.

EricLloyd79
Builder

Thank you for your answer. It clarified whether it is possible or not. Unfortunately, you are right, using the query itself defeating the purpose of getting the acceleration benefits and bypass the use of the pivot UI completely. I have a list of questions/concerns about the data models/pivot system they have in place that I am taking with me to Splunk conference.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...