Splunk Search

How to chart multiple values over time

tkwaller_2
Communicator

Hello
I'm trying to get a chart to work but having a bit of difficulty getting it right.
Heres what Im trying to do:

index=cval_risk | eval BIA=replace('BIA Cost to mitigate _CtM',",","") | eval BIA = trim(BIA)
|chart sum(BIA) over "Mitigation Plan Start" "Mitigation Plan End" by "Mitigation Plan2" limit=100
| sort "Mitigation Plan Start"

Any suggestions on how I can get this accomplished?
Thank for the help!

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...