Splunk Search

Hi , I want to show 3 data points/values/counts on each daily column for last 7 days in column chart, TIA.

neha_h
Explorer

Hi,
Currently I am showing 1 datapoint per column with below query:

application="my-app" "*test-path*" | rename test-path as path | eval result=case((path == "/test-data/test/data"), "Total count" ) | timechart span=1d count |  eval day=strftime(_time,"%d/%m") | fields day, count

but I want to show 3 data for each daily column, I am trying below

application="my-app" "*test-path*" | rename test-path as path | eval result=case((path == "/test-data/test/data"), "Total count" , (path == "/test/test2-mydata/order"), "Total order ) | timechart span=1d count |  eval day=strftime(_time,"%d/%m") | fields day, count

but not working

0 Karma
1 Solution

DalJeanis
Legend

1) You are missing a close-quote on "Total order".
2) Your timechart needs a "by" field in order to separate the counts for the two different results.
3) The final record needs to have the two fields you wanted in it.

application="my-app" "*test-path*" 
| rename test-path as path 
| eval result=case((path == "/test-data/test/data"), "Total count" , (path == "/test/test2-mydata/order"), "Total order") 
| timechart span=1d count by result 
|  eval day=strftime(_time,"%d/%m") 
| fields day, "Total count",  "Total order"

View solution in original post

0 Karma

DalJeanis
Legend

1) You are missing a close-quote on "Total order".
2) Your timechart needs a "by" field in order to separate the counts for the two different results.
3) The final record needs to have the two fields you wanted in it.

application="my-app" "*test-path*" 
| rename test-path as path 
| eval result=case((path == "/test-data/test/data"), "Total count" , (path == "/test/test2-mydata/order"), "Total order") 
| timechart span=1d count by result 
|  eval day=strftime(_time,"%d/%m") 
| fields day, "Total count",  "Total order"
0 Karma

neha_h
Explorer

Thanks @DalJeanis

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...