Splunk Search

How to Create a Stacked Chart with 3 data points

kknopp
Path Finder

This seems similar to http://answers.splunk.com/answers/108423/stacked-chart-to-show-how-many-calls-where-assigned-to-the-..., but I can't seem to apply it in practice.

I have 3 values:
stats sum (Requests)
hourOfRequest (date_hour essentially)
host

I want to see a stacked chart, where each column is a host, and the sum(request) per hourOfRequest are the series within each column. I've tried a few different methods, but can't seem to get it.

Tags (3)
1 Solution

kknopp
Path Finder

Got it! Now that I understand chart commands better. Take out stats, just use charts and:

chart sum(requests) over host by hourOfRequest

View solution in original post

kknopp
Path Finder

Got it! Now that I understand chart commands better. Take out stats, just use charts and:

chart sum(requests) over host by hourOfRequest

Get Updates on the Splunk Community!

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...