Splunk Search

How to change timechart axis?

corehan
Explorer

Hello dears,

How can i change timechart _time axis y to x ?

<base search>  | timechart span=1h sum(REQUESTNAME) as Sikayet count by ilce |sort -count | untable _time Xaxis Yaxis |where Yaxis > 3

 

Regards

Labels (1)
Tags (1)
0 Karma

corehan
Explorer

Finally here is my query which i want;

<base search> | timechart span=1h count(REQUESTNAME) by ilce usenull=f useother=f | eval Time=strftime(_time,"%H:%M") | table Time,* | untable Time Xaxis Yaxis | xyseries Xaxis Time Yaxis

Fyi..

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| xyseries Xaxis _time Yaxis
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@corehan - Why you are using untable command?

By default timechart command put _time on the X-axis. Please try removing stuff after sort command and see if you get what you need.

-----
I hope this helps!!! If it does consider upvoting!!!

0 Karma

corehan
Explorer

Thank you for suggest but i can't found, how can i put the _time to x axis command..

Regards.

Final search;

<base search>  | timechart span=1h count(REQUESTNAME) by ilce |sort -count 

Also i need to set threshold value like count >3 in this scenario.

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@corehan - Since you are using timechart command with groupby, your Y-axis field name is not the "count".

If you look at the results it's not one-dimensional results here. So if you want to filter for those for which the total count is not greater than 3 then you can use the following search:

<base search>  | timechart span=1h count(REQUESTNAME) by ilce 
| transpose
| addtotals
| search Total>3
| fields- Total
| transpose header_field=column
| fields - column

 

Please post the screenshot of the result if this does not work.

0 Karma

corehan
Explorer

Hello,

I changed the query but i doesn't work;

<base search> | timechart span=1h count(REQUESTNAME) by ilce |transpose | addtotals |fields- Total |transpose header_field=column |fields -column

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...