Splunk Search

Creating a chart by search terms

beaumygod
New Member

If I have several terms I am searching for such as:

john OR frank OR mary OR jim OR jeff

How would I then create a chart of the sum or percentage of each search term, such as john returns 20 of 100 total results and is therefore 20% of the pie chart...

Tags (1)
0 Karma

ytamura
Path Finder

If you create a field that contains those names, you can just use the top command:

john OR frank OR mary OR jim OR jeff | top name

Field extractions can be predefined or done on the fly. Resource for field extraction: http://docs.splunk.com/Documentation/Splunk/latest/User/ExtractNewFields

Resource for top command:
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/top

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...