Splunk Search

How to create a timeline table?

faustf
Communicator

Hi,
we are logging api requests in Splunk.

I would like to create a sort of health check table where every column represents the status code of the last API call in previous 5 minutes. While each row is a different API.

Here an example of what the output should be

IMG_0259.jpeg

Any Idea how I could achieve that in Splunk?

Each row represents a different API ( request.url), while the status code is stored in response.status

Thank you

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

See if this helps.  It uses actual times rather than relative ones, but the format is there.

index=_internal status=* earliest=-30m 
``` Get the most recent status for each API every 5 minutes
| timechart span=5m latest(status) as status by API
``` Convert timestamp to time (HH:MM) ```
| eval _time=strftime(_time,"%H:%M") 
``` Flip the display so time is across the top and API down the side ```
| transpose 0 header_field=_time column_name="API" 
``` Fill in blank cells ```
| fillnull value="-"
---
If this reply helps you, Karma would be appreciated.

faustf
Communicator

Very good this is what I was looking for. Thank you.

Do you know how I can now color each cell depending on the status code?

Usually I use the following configuration in the dashboard

<format type="color" field="status">
  <colorPalette type="expression">case(value like "5%","#D6563C",value like "4%","#F2B827",value like "3%","#A2CC3E",value like "2%","#65A637",true(),null)</colorPalette>
</format>

 

but it is not working now (I suppose because of the transpose command).

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I suspect you are right, but you probably should post a separate question about that.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...