Splunk Search

How to change timechart axis?

corehan
Explorer

Hello dears,

How can i change timechart _time axis y to x ?

<base search>  | timechart span=1h sum(REQUESTNAME) as Sikayet count by ilce |sort -count | untable _time Xaxis Yaxis |where Yaxis > 3

 

Regards

Labels (1)
Tags (1)
0 Karma

corehan
Explorer

Finally here is my query which i want;

<base search> | timechart span=1h count(REQUESTNAME) by ilce usenull=f useother=f | eval Time=strftime(_time,"%H:%M") | table Time,* | untable Time Xaxis Yaxis | xyseries Xaxis Time Yaxis

Fyi..

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| xyseries Xaxis _time Yaxis
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@corehan - Why you are using untable command?

By default timechart command put _time on the X-axis. Please try removing stuff after sort command and see if you get what you need.

-----
I hope this helps!!! If it does consider upvoting!!!

0 Karma

corehan
Explorer

Thank you for suggest but i can't found, how can i put the _time to x axis command..

Regards.

Final search;

<base search>  | timechart span=1h count(REQUESTNAME) by ilce |sort -count 

Also i need to set threshold value like count >3 in this scenario.

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@corehan - Since you are using timechart command with groupby, your Y-axis field name is not the "count".

If you look at the results it's not one-dimensional results here. So if you want to filter for those for which the total count is not greater than 3 then you can use the following search:

<base search>  | timechart span=1h count(REQUESTNAME) by ilce 
| transpose
| addtotals
| search Total>3
| fields- Total
| transpose header_field=column
| fields - column

 

Please post the screenshot of the result if this does not work.

0 Karma

corehan
Explorer

Hello,

I changed the query but i doesn't work;

<base search> | timechart span=1h count(REQUESTNAME) by ilce |transpose | addtotals |fields- Total |transpose header_field=column |fields -column

 

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...