Splunk Search

How can I add extra labels to columns in charts?

Path Finder


I create a chart using the following query which basically combines three fields and plots their count on a chart.
When I hover the mouse on any column I can see the phase name and count(as expected).

 | eval myFan=mvrange(0,3)
 | mvexpand myFan
 | eval time=case(myFan=0,$$payload.beginVal$$, myFan=1,$$payload.endVal$$, myFan=2,$$payload.anotherVal$$)
 | eval phase=case(myFan=0,"Start", myFan=1,"End", myFan=2,"Other")
 | eval Time= strftime (time, “%F %T.%9Q”)
 | chart count by Time phase

I now want to add an extra label($$payload.eventID$$) to every column such that when I hover over a column I am also able to see this label. How do I do this?

(PS I first tried concatenating this label to phase but then the chart starts counting by 'phase+payload.eventID' which I do not want. I want the chart to look the same, just with the new added label to each column.)



I agree with the somesoni answer

0 Karma

Revered Legend

Just add following to end of your current search

| rename Start as "$$payload.eventID$$:Start" End as "$$payload.eventID$$:End" Other as "$$payload.eventID$$:Other"

Path Finder

This above solution helped me to solve a similar problem, Thanks @somesoni2

0 Karma
Get Updates on the Splunk Community!

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...

DevSecOps: Why You Should Care and How To Get Started

 WATCH NOW In this Tech Talk we will talk about what people mean by DevSecOps and deep dive into the different ...