- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
raoul
Path Finder
05-31-2011
05:43 AM
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
raoul
Path Finder
05-31-2011
06:05 AM
Managed to puzzle it out, here is my example:
<chart>
<searchString>
sourcetype="transactions"
| bucket _time span=1h
| stats count(eval(Rsp!="00")) as declines, count by _time, Region
| eval pct=round((declines/count) * 100, 2)
| table Region, _time, pct, declines
</searchString>
<title>Percentage declines by Region, last 48h</title>
<earliestTime>-48h@h</earliestTime>
<latestTime>now</latestTime>
<option name="charting.chart">bubble</option>
</chart>
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/9dd94/9dd94b2e112752e754d596f78e5ce328b89fc899" alt="woodcock woodcock"
woodcock
Esteemed Legend
11-25-2019
10:56 AM
Check out the AWESOME run-anywhere
example here:
https://answers.splunk.com/answers/785029/what-is-the-best-way-to-get-100ish-greeenyellowred.html
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
raoul
Path Finder
05-31-2011
06:05 AM
Managed to puzzle it out, here is my example:
<chart>
<searchString>
sourcetype="transactions"
| bucket _time span=1h
| stats count(eval(Rsp!="00")) as declines, count by _time, Region
| eval pct=round((declines/count) * 100, 2)
| table Region, _time, pct, declines
</searchString>
<title>Percentage declines by Region, last 48h</title>
<earliestTime>-48h@h</earliestTime>
<latestTime>now</latestTime>
<option name="charting.chart">bubble</option>
</chart>
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
renuka13
Explorer
02-27-2013
10:51 PM
sourcetype="E:\New Folder\voice_cdr_1mil.csv" NOT "CallingCellID" TerminationReason!=1 |
|bucket TimeStamp span=5h|
eval Base_Transceiver_Station_Code=substr(CallingCellID,11,4) |
join Base_Transceiver_Station_Code [search source="E:\New Folder\BTS_Information2.txt"] |
table TERRITORY,TimeStamp,TerminationReason
bubble
i am joining two files here and the result i need as bubble chart but i am not getting any output .. is this code is correct? please help me out
data:image/s3,"s3://crabby-images/a266d/a266d0c80c12793a952b209c17cc3de41b17fc89" alt=""