Splunk Search

Display all values (including duplicate values) in timechart graph

AKG1_old1
Builder

Hello,

In my data, there could be multiple values(duration) for Scriptname. I am using Time Chart to display data and it should include all values including duplicates.

All Data alt text

Time Chart alt text

My Query:

eventtype=mlc_live host=TALANX_PostGoLive sourcetype=tool_lifecycle |  rex field="ScriptName" "^\S+_(?<ScriptName>[^\.]+)\.\S+" |  table _time Duration GROUPBY ScriptName UniqueIdentifier | dedup UniqueIdentifier | timechart max(Duration) BY ScriptName

Currently, I am using max function which include only one value. How can I display all events (including duplicates) in time chart graph.

cmerriman
Super Champion

try this instead of timechart, but i'm not sure if the visualization is going to like it or not.

|eval {ScriptName}=Duration
|fields - ScriptName Duration UniqueIdentifier
0 Karma

AKG1_old1
Builder

trick worked for fetching all data but unfortunately not working visually. 😞

elliotproebstel
Champion

I think you're looking for list() or values() instead of max(). Check out this documentation to help you decide which of those will work better for your use case:
http://docs.splunk.com/Documentation/Splunk/7.0.0/SearchReference/Multivaluefunctions

0 Karma

AKG1_old1
Builder

Thanks for reply. I tried both list() and values() but these function will include all duplicate values in same row which wont be displayed on Graph.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...

Join the Final Session of the Data Management & Federation Bootcamp Series

Over the past three sessions of the Data Management & Federation Bootcamp Series, we've explored how to build ...

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...