Splunk Search

Display all values (including duplicate values) in timechart graph

AKG1_old1
Builder

Hello,

In my data, there could be multiple values(duration) for Scriptname. I am using Time Chart to display data and it should include all values including duplicates.

All Data alt text

Time Chart alt text

My Query:

eventtype=mlc_live host=TALANX_PostGoLive sourcetype=tool_lifecycle |  rex field="ScriptName" "^\S+_(?<ScriptName>[^\.]+)\.\S+" |  table _time Duration GROUPBY ScriptName UniqueIdentifier | dedup UniqueIdentifier | timechart max(Duration) BY ScriptName

Currently, I am using max function which include only one value. How can I display all events (including duplicates) in time chart graph.

cmerriman
Super Champion

try this instead of timechart, but i'm not sure if the visualization is going to like it or not.

|eval {ScriptName}=Duration
|fields - ScriptName Duration UniqueIdentifier
0 Karma

AKG1_old1
Builder

trick worked for fetching all data but unfortunately not working visually. 😞

elliotproebstel
Champion

I think you're looking for list() or values() instead of max(). Check out this documentation to help you decide which of those will work better for your use case:
http://docs.splunk.com/Documentation/Splunk/7.0.0/SearchReference/Multivaluefunctions

0 Karma

AKG1_old1
Builder

Thanks for reply. I tried both list() and values() but these function will include all duplicate values in same row which wont be displayed on Graph.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...