Splunk Search

How to create trellis timechart with stacked bars

tdoSplunk
Path Finder

Hi,

I want to create a timechart as trellis with stacked bars.

I have the following columns:
Workdate, Duration, BookingType, LoginName

2019-06-03,5,1,User1
2019-06-03,2,2,User1
2019-06-03,1,3,User1
2019-06-03,3,1,User2
2019-06-03,3,2,User2
2019-06-03,2,3,User2
...

My Expectation is to see 2 Charts, one for User1 and one for User2 with a stacked bar for the Workdate 2019-06-01
The Total sum for each is 8, separated by the durations by BookingTypealt text

My first approach was to use |timechart sum(Duration) as Total by BookingType, then I get nearly the result I want. But it is not possible to use Trellis (by LoginName).

Do you have ideas on how to solve it?

best regards
Thomas

khristian_p
Engager

chart sum(Duration) by BookingType, LoginName

I wouldn't use Trellis because of how you want your chart stacked.

0 Karma

tdoSplunk
Path Finder

thank you for your respond, but it is a requirement to use trellis (to have a chart like this, splitted by LoginName). I think timechart is a good way, but perhaps I have to do some extra work before or after it

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...