Splunk Search

How to display the values of a field in a chart, not the count of the number of events?


Hello ! I have a field called Total Value that contains currency values ​​.

I want to use these values ​​in my chart , however Splunk is counting the events , and not the values ​​themselves .

How do I change this ? For example : Value = Total Value

Path Finder

if your problem is to display values of the field Total values in your chart use a values() fonction after renaming Total values as Totalvalues
|chart values(Toatal

0 Karma


Can you post some sample events and may be current non-working search? Also, expected output.

0 Karma