Splunk Search

Hi , I want to show 3 data points/values/counts on each daily column for last 7 days in column chart, TIA.

neha_h
Explorer

Hi,
Currently I am showing 1 datapoint per column with below query:

application="my-app" "*test-path*" | rename test-path as path | eval result=case((path == "/test-data/test/data"), "Total count" ) | timechart span=1d count |  eval day=strftime(_time,"%d/%m") | fields day, count

but I want to show 3 data for each daily column, I am trying below

application="my-app" "*test-path*" | rename test-path as path | eval result=case((path == "/test-data/test/data"), "Total count" , (path == "/test/test2-mydata/order"), "Total order ) | timechart span=1d count |  eval day=strftime(_time,"%d/%m") | fields day, count

but not working

0 Karma
1 Solution

DalJeanis
SplunkTrust
SplunkTrust

1) You are missing a close-quote on "Total order".
2) Your timechart needs a "by" field in order to separate the counts for the two different results.
3) The final record needs to have the two fields you wanted in it.

application="my-app" "*test-path*" 
| rename test-path as path 
| eval result=case((path == "/test-data/test/data"), "Total count" , (path == "/test/test2-mydata/order"), "Total order") 
| timechart span=1d count by result 
|  eval day=strftime(_time,"%d/%m") 
| fields day, "Total count",  "Total order"

View solution in original post

0 Karma

DalJeanis
SplunkTrust
SplunkTrust

1) You are missing a close-quote on "Total order".
2) Your timechart needs a "by" field in order to separate the counts for the two different results.
3) The final record needs to have the two fields you wanted in it.

application="my-app" "*test-path*" 
| rename test-path as path 
| eval result=case((path == "/test-data/test/data"), "Total count" , (path == "/test/test2-mydata/order"), "Total order") 
| timechart span=1d count by result 
|  eval day=strftime(_time,"%d/%m") 
| fields day, "Total count",  "Total order"
0 Karma

neha_h
Explorer

Thanks @DalJeanis

Get Updates on the Splunk Community!

New Cloud Intrusion Detection System Add-on for Splunk

In July 2022 Splunk released the Cloud IDS add-on which expanded Splunk capabilities in security and data ...

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Check out This Month’s Brand new Splunk Lantern Articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...