Splunk Search

Display all values (including duplicate values) in timechart graph

AKG1_old1
Builder

Hello,

In my data, there could be multiple values(duration) for Scriptname. I am using Time Chart to display data and it should include all values including duplicates.

All Data alt text

Time Chart alt text

My Query:

eventtype=mlc_live host=TALANX_PostGoLive sourcetype=tool_lifecycle |  rex field="ScriptName" "^\S+_(?<ScriptName>[^\.]+)\.\S+" |  table _time Duration GROUPBY ScriptName UniqueIdentifier | dedup UniqueIdentifier | timechart max(Duration) BY ScriptName

Currently, I am using max function which include only one value. How can I display all events (including duplicates) in time chart graph.

cmerriman
Super Champion

try this instead of timechart, but i'm not sure if the visualization is going to like it or not.

|eval {ScriptName}=Duration
|fields - ScriptName Duration UniqueIdentifier
0 Karma

AKG1_old1
Builder

trick worked for fetching all data but unfortunately not working visually. 😞

elliotproebstel
Champion

I think you're looking for list() or values() instead of max(). Check out this documentation to help you decide which of those will work better for your use case:
http://docs.splunk.com/Documentation/Splunk/7.0.0/SearchReference/Multivaluefunctions

0 Karma

AKG1_old1
Builder

Thanks for reply. I tried both list() and values() but these function will include all duplicate values in same row which wont be displayed on Graph.

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...