Splunk Search

Hi , I want to show 3 data points/values/counts on each daily column for last 7 days in column chart, TIA.

neha_h
Explorer

Hi,
Currently I am showing 1 datapoint per column with below query:

application="my-app" "*test-path*" | rename test-path as path | eval result=case((path == "/test-data/test/data"), "Total count" ) | timechart span=1d count |  eval day=strftime(_time,"%d/%m") | fields day, count

but I want to show 3 data for each daily column, I am trying below

application="my-app" "*test-path*" | rename test-path as path | eval result=case((path == "/test-data/test/data"), "Total count" , (path == "/test/test2-mydata/order"), "Total order ) | timechart span=1d count |  eval day=strftime(_time,"%d/%m") | fields day, count

but not working

0 Karma
1 Solution

DalJeanis
Legend

1) You are missing a close-quote on "Total order".
2) Your timechart needs a "by" field in order to separate the counts for the two different results.
3) The final record needs to have the two fields you wanted in it.

application="my-app" "*test-path*" 
| rename test-path as path 
| eval result=case((path == "/test-data/test/data"), "Total count" , (path == "/test/test2-mydata/order"), "Total order") 
| timechart span=1d count by result 
|  eval day=strftime(_time,"%d/%m") 
| fields day, "Total count",  "Total order"

View solution in original post

0 Karma

DalJeanis
Legend

1) You are missing a close-quote on "Total order".
2) Your timechart needs a "by" field in order to separate the counts for the two different results.
3) The final record needs to have the two fields you wanted in it.

application="my-app" "*test-path*" 
| rename test-path as path 
| eval result=case((path == "/test-data/test/data"), "Total count" , (path == "/test/test2-mydata/order"), "Total order") 
| timechart span=1d count by result 
|  eval day=strftime(_time,"%d/%m") 
| fields day, "Total count",  "Total order"
0 Karma

neha_h
Explorer

Thanks @DalJeanis

Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...