Splunk Search

How to create trellis timechart with stacked bars

tdoSplunk
Path Finder

Hi,

I want to create a timechart as trellis with stacked bars.

I have the following columns:
Workdate, Duration, BookingType, LoginName

2019-06-03,5,1,User1
2019-06-03,2,2,User1
2019-06-03,1,3,User1
2019-06-03,3,1,User2
2019-06-03,3,2,User2
2019-06-03,2,3,User2
...

My Expectation is to see 2 Charts, one for User1 and one for User2 with a stacked bar for the Workdate 2019-06-01
The Total sum for each is 8, separated by the durations by BookingTypealt text

My first approach was to use |timechart sum(Duration) as Total by BookingType, then I get nearly the result I want. But it is not possible to use Trellis (by LoginName).

Do you have ideas on how to solve it?

best regards
Thomas

khristian_p
Engager

chart sum(Duration) by BookingType, LoginName

I wouldn't use Trellis because of how you want your chart stacked.

0 Karma

tdoSplunk
Path Finder

thank you for your respond, but it is a requirement to use trellis (to have a chart like this, splitted by LoginName). I think timechart is a good way, but perhaps I have to do some extra work before or after it

0 Karma
Get Updates on the Splunk Community!

March Community Office Hours Security Series Uncovered!

Hello Splunk Community! In March, Splunk Community Office Hours spotlighted our fabulous Splunk Threat ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars in April. This post ...

Want to Reduce Costs, Mitigate Risk, Improve Performance, or Increase Efficiencies? ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...