Splunk Search
Highlighted

How can I make visualizations with time format hh:mm:ss?

Communicator

Hi,

I have the below statement with the correct statistics output. However my visualization is empty. But when I use the duration in numbers, it does create charts.

| dedup IDEVENT
| stats sum(DURATION) AS "SDURATION" BY DESCRIPTION
| eval field
inhhmmss=tostring(SDURATION, "duration")
| rename fieldinhhmmss as "DURATIONMIN"
| sort - DURATION
MIN LIMIT=10
| fields - S_DURATION

0 Karma
Highlighted

Re: How can I make visualizations with time format hh:mm:ss?

Legend

@auaave statistical chart looks for numeric value to be plotted on y-axis. In case you want to plot duration, you should be trying out Timeline Custom Visualization: https://splunkbase.splunk.com/app/3120/




| eval message="Happy Splunking!!!"


0 Karma
Highlighted

Re: How can I make visualizations with time format hh:mm:ss?

SplunkTrust
SplunkTrust

Normally, when calculated from epoch time, duration would start as a number in seconds rather than minutes. Verify your calculations.

Suggestions:

Calculate the duration in minutes and chart that number.

Calculate the duration in HH:MM:SS format and append that to each DESCRIPTION.

Put an alternate Y axis on the right, called out in hours.

0 Karma