Splunk Search

Creating a bar chart with multiple fields

andrwbn
Engager

I am trying to create a bar chart displaying the amount of active users the past 1 hour, 24 hour, and 1 week.

How would I go about doing this?

Thanks!

0 Karma
1 Solution

gokadroid
Motivator

If you have the keywords to detect and filter out unique active users then you can follow below approach assuming field user identifies a user:

index= yourIndex earliest=-1h your query to return active user
| dedup user
| stats count as ActiveUser
| eval reportKey="Last1Hour"
| append [ search  index= yourIndex earliest=-24h your query to return active user
| dedup user
| stats count as ActiveUser
| eval reportKey="Last24Hour" ]
| append [ search index= yourIndex earliest=-7d your query to return active user
| dedup user
| stats count as ActiveUser
| eval reportKey="Last1Week" ]
| chart ActiveUser over reportKey

View solution in original post

gokadroid
Motivator

If you have the keywords to detect and filter out unique active users then you can follow below approach assuming field user identifies a user:

index= yourIndex earliest=-1h your query to return active user
| dedup user
| stats count as ActiveUser
| eval reportKey="Last1Hour"
| append [ search  index= yourIndex earliest=-24h your query to return active user
| dedup user
| stats count as ActiveUser
| eval reportKey="Last24Hour" ]
| append [ search index= yourIndex earliest=-7d your query to return active user
| dedup user
| stats count as ActiveUser
| eval reportKey="Last1Week" ]
| chart ActiveUser over reportKey

somesoni2
Revered Legend

Give this a try

Updated
Thanks @gokadroid for pointing out the flaw in the previous answer.

your base search earliest=-7d| eval Period=case(_time>=relative_time(now(),"-1h"),"1#Last 1 Hour"),_time>=relative_time(now(),"-24h"),"2#Last 24 Hour",1=1,"3#Last 1 Week") | stats count(UserField) as active_users by Period
| accum active_users | eval Period=mvindex(split(Period,"#"),1)

gokadroid
Motivator

Should not the last one hour users be also part of last 24 hours? and so shall be the last 24 hours part of last 7days? Just thinking!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Unlocking Data-In-Place Search Across Splunk and Snowflake  Enterprise data is increasingly distributed across ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...