Managed to puzzle it out, here is my example:
<chart>
<searchString>
sourcetype="transactions"
| bucket _time span=1h
| stats count(eval(Rsp!="00")) as declines, count by _time, Region
| eval pct=round((declines/count) * 100, 2)
| table Region, _time, pct, declines
</searchString>
<title>Percentage declines by Region, last 48h</title>
<earliestTime>-48h@h</earliestTime>
<latestTime>now</latestTime>
<option name="charting.chart">bubble</option>
</chart>
Check out the AWESOME run-anywhere
example here:
https://answers.splunk.com/answers/785029/what-is-the-best-way-to-get-100ish-greeenyellowred.html
Managed to puzzle it out, here is my example:
<chart>
<searchString>
sourcetype="transactions"
| bucket _time span=1h
| stats count(eval(Rsp!="00")) as declines, count by _time, Region
| eval pct=round((declines/count) * 100, 2)
| table Region, _time, pct, declines
</searchString>
<title>Percentage declines by Region, last 48h</title>
<earliestTime>-48h@h</earliestTime>
<latestTime>now</latestTime>
<option name="charting.chart">bubble</option>
</chart>
sourcetype="E:\New Folder\voice_cdr_1mil.csv" NOT "CallingCellID" TerminationReason!=1 |
|bucket TimeStamp span=5h|
eval Base_Transceiver_Station_Code=substr(CallingCellID,11,4) |
join Base_Transceiver_Station_Code [search source="E:\New Folder\BTS_Information2.txt"] |
table TERRITORY,TimeStamp,TerminationReason
bubble
i am joining two files here and the result i need as bubble chart but i am not getting any output .. is this code is correct? please help me out