Splunk Search

How to create a timechart with multiple values?

ppatrikfr
Path Finder

Hello!
I'm trying to make a timechart like this one below, but I have some hosts that I need to show their medium cpu usage per hour (0am - 11 pm. I'm getting one-month data and trying to show their average per hour, but I only can put the average of all hosts, but I need the average for each one.

My search until now:

earliest=04/01/2018:00:00:00 latest=04/30/2018:23:59:00 index="summary" instance="cpu.usage.average" source=Summary_VMhost 
| rename media as Value 
| table * 
| where VMhost="" OR like(VMhost,"hostname00020.somecorp.net") OR like(VMhost,"hostname00021.somecorp.net") OR like(VMhost,"hostname052073.somecorp.net") OR like(VMhost,"hostname052074.somecorp.net") OR like(VMhost,"hostname052075.somecorp.net") OR like(VMhost,"hostname052076.somecorp.net") OR like(VMhost,"hostname631.somecorp.net") OR like(VMhost,"hostname632.somecorp.net") OR like(VMhost,"hostname641.somecorp.net") OR like(VMhost,"hostname642.somecorp.net") 
| eval date_hour=strftime(_time,"%H") 
| eval Horario_critico=if((date_hour>=7 AND date_hour<11) OR (date_hour>=13 AND date_hour<17),100,null) 
| stats avg(Value) max(Horario_critico) by date_hour
0 Karma
1 Solution

niketn
Legend

Instead of stats use chart to have date_hour on x-axis and split by VMhost

 <YourCurrentSearch>
| chart avg(Value) by date_hour VMhost
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

niketn
Legend

Instead of stats use chart to have date_hour on x-axis and split by VMhost

 <YourCurrentSearch>
| chart avg(Value) by date_hour VMhost
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

ppatrikfr
Path Finder

I didn't know that diference about both(stats and chart), thanks it works perfectly!!!

0 Karma

niketn
Legend

@ppatrikfr glad it worked, I have converted my comment to answer. Please accept to mark this question as answered!

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...

Application management with Targeted Application Install for Victoria Experience

Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...