I want to create this graph in splunk can some one please help me .
Required graph
The one that i am getting after writing the following query is this
Query - index="BTS-card-account-update" exception="*" ("Payment instrument not found" OR "Wallet already has the updated card") | timechart count by host
Graph after my qurey
can some one please tell me how to get two separate line for both kind of exception separately.
Thanks in advance 🙂
Hi @Anidy21,
the problem is that, in the first graph events are plotted by kind of event, instead in your graph are plotted by host, you should try something like this:
index="BTS-card-account-update" exception="*" ("Payment instrument not found" OR "Wallet already has the updated card")
| eval kind=if(searchmatch("Payment instrument not found"),"Payment instrument not found","Wallet already has the updated card")
| timechart count by kind
Ciao.
Giuseppe
Hi @Anidy21,
the problem is that, in the first graph events are plotted by kind of event, instead in your graph are plotted by host, you should try something like this:
index="BTS-card-account-update" exception="*" ("Payment instrument not found" OR "Wallet already has the updated card")
| eval kind=if(searchmatch("Payment instrument not found"),"Payment instrument not found","Wallet already has the updated card")
| timechart count by kind
Ciao.
Giuseppe
HI @gcusello
After trying your query i am getting this result , can you please help me writing the query as i am very new to splunk
Still getting count for one type only
Hi @Anidy21 ,
viewieng your graph, it seems that you have only events containing the string "Payment instrument not found"
could you share som sample of events containing both the strings?
Ciao.
Giuseppe
Hello @gcusello
yes you are write i only have even containing the string ""payment instrument not found"
when i replace other string which is present in the db i am getting desired graph/result
Thank you so so much for your help 🙂
Hi @Anidy21 ,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉