Splunk Search

Display all values (including duplicate values) in timechart graph

AKG1_old1
Builder

Hello,

In my data, there could be multiple values(duration) for Scriptname. I am using Time Chart to display data and it should include all values including duplicates.

All Data alt text

Time Chart alt text

My Query:

eventtype=mlc_live host=TALANX_PostGoLive sourcetype=tool_lifecycle |  rex field="ScriptName" "^\S+_(?<ScriptName>[^\.]+)\.\S+" |  table _time Duration GROUPBY ScriptName UniqueIdentifier | dedup UniqueIdentifier | timechart max(Duration) BY ScriptName

Currently, I am using max function which include only one value. How can I display all events (including duplicates) in time chart graph.

cmerriman
Super Champion

try this instead of timechart, but i'm not sure if the visualization is going to like it or not.

|eval {ScriptName}=Duration
|fields - ScriptName Duration UniqueIdentifier
0 Karma

AKG1_old1
Builder

trick worked for fetching all data but unfortunately not working visually. 😞

elliotproebstel
Champion

I think you're looking for list() or values() instead of max(). Check out this documentation to help you decide which of those will work better for your use case:
http://docs.splunk.com/Documentation/Splunk/7.0.0/SearchReference/Multivaluefunctions

0 Karma

AKG1_old1
Builder

Thanks for reply. I tried both list() and values() but these function will include all duplicate values in same row which wont be displayed on Graph.

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...