Splunk Search

How to create a search with string column to generate a chart with 3 data points?

chambooca
Observer

I'm an intermediate Splunk user.  I have a query that has 3 fields i want to turn into a chart:
1. mySearchTerm (string)
2. geoID(10 values, each is a unique 5 digit number: 10010, 20020, etc...)
3. the count of searchTerms that appear per geoID

I am able to get a table going using:

 

 

<main query> | stats count(mySearchTerm) as myCount BY geoID, mySearchTerm
| table geoID myCount mySearchTerm

 

 

 

But when I go to build a visualization of any kind (bubble, scatter, etc) the layout looks wrong.
I'd like to create a visualization of count of mySearchTerm broken down by geoID

2 part question:

1. Does my query seem appropriate for my intended use?

2. Is there a specific chart type that is more suited for this information?

Labels (2)
Tags (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You don't need the table command

Either line or column chart would probably work

0 Karma
Get Updates on the Splunk Community!

ATTENTION!! We’re MOVING (not really)

Hey, all! In an effort to keep this Slack workspace secure and also to make our new members' experience easy, ...

Splunk Admins: Build a Smarter Stack with These Must-See .conf25 Sessions

  Whether you're running a complex Splunk deployment or just getting your bearings as a new admin, .conf25 ...

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...