Splunk Search

How to create a bin of bins?

Lynyrd
Explorer

I need to create a "bin of bins"... in other words... each bin contains a bin. I desire to create a histogram (chart) in each bin. Why do I want to do this?

I want to apply SPLUNK to logged test data. I have thousands of events structured as follows:
TST_NAME UP_LIM LO_LIM ACT_VAL

So in my "bin of bins", the first bin holds the TST_NAME, while the second bin holds the histogram (chart) of that named bin.

Is there a way to create a bin of bins?

Tags (3)
0 Karma

niketn
Legend

@Lynyrd, can you add sample output data or image to explain what exactly you need? What is the query for histogram that you have? If you are on Splunk 6.6. or higher you can explore the Trellis command to split same visualization into several parts using by TST_NAME. However, community members would not be able to assist much without further details.

Refer to Trellis Layout in Splunk Documentation:
https://docs.splunk.com/Documentation/Splunk/latest/Viz/VisualizationTrellis#Trellis_layout_and_dash...

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

Lynyrd
Explorer

I just submitted my data again and it did not show up.... I think there is a problem with this forum. Maybe the Admin have a bug in their system

0 Karma

niketn
Legend

Hi Lynyrd, your comment was sitting for Moderators to review and publish. I have done the same.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

Lynyrd
Explorer

ops sorry, I see it has been posted.

0 Karma

Lynyrd
Explorer

I just submitted my data and it did not show up.

0 Karma

Lynyrd
Explorer

I need a histogram for each TP and there will be thousands of TP's. The database I work with has thousands of events just like you see below and I need to analyse the normal distribution of each TP to determine if there is a problem with any given TP.

TST_NAME UP_LIM LO_LIM ACTAUL
TP29 -20 20 3.7
TP29 -20 20 3.3
TP29 -20 20 -4.2
TP29 -20 20 5.1
TP29 -20 20 2.8
TP29 -20 20 -1.9
TP29 -20 20 4
TP29 -20 20 -2.2
TP30 0 5.5 5.1
TP30 0 5.5 5.36
TP30 0 5.5 4.9
TP30 0 5.5 4.89
TP30 0 5.5 5.1
TP30 0 5.5 5.2
TP31 1254 1300 1266
TP31 1254 1300 1285
TP31 1254 1300 1269
TP31 1254 1300 1292
TP31 1254 1300 1277
TP31 1254 1300 1264
TP31 1254 1300 1285
TP32 540 640 601
TP32 540 640 588
TP32 540 640 596
TP32 540 640 623
TP32 540 640 552
TP32 540 640 631
ETC

0 Karma

Lynyrd
Explorer

I got my UP_LIM and LO_LIM columns swapped... hey but you get the idea.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...