Splunk Search
Highlighted

Display data in timechart

Path Finder

I'm using summary index to get data and display in timechart. but not able to create a time chart with the data.

index = summarydm searchname = Instancecount | table totalInstancecount _time

(total_Instancecount, _time) these are the two fields

summary in is created by using
index = application cforg = cfspace = cfapp = instanceindex = |bucket time span=1min| dedup cforg cfspace cfapp instanceindex | timechart span=1min count(instanceindex) by cfapp| addtotals fieldname = Totalinstances | fields time Totalinstances

report is scheduled using above query

summary index is populated with time totalInstancecount.

0 Karma
Highlighted

Re: Display data in timechart

Legend

@kirrusk what is the frequency of your summary indexing? Also how is summary index being created? For plotting timechart what is the span you are looking for

index = summary_dm search_name = Instance_count
| timechart sum(total_Instancecount) as total_Instancecount



| eval message="Happy Splunking!!!"


0 Karma
Highlighted

Re: Display data in timechart

Path Finder

summary in is created by using
index = application cforg = * cfspace = * cfapp = * instanceindex = * |bucket time span=1min| dedup cforg cfspace cfapp instanceindex | timechart span=1min count(instanceindex) by cfapp| addtotals fieldname = Totalinstances | fields time Totalinstances

report is scheduled using above query

summary index is populated with time Totalinstances.

0 Karma
Highlighted

Re: Display data in timechart

Legend

@kirrusk did you try the above query? Does it work for you?




| eval message="Happy Splunking!!!"


0 Karma
Highlighted

Re: Display data in timechart

Esteemed Legend

Try this:

 index = summary_dm search_name = Instance_count
 | timechart sum(Total_instances) AS Total_instances