Splunk Search

How to make a timechart/graph from a search result?

anirban_nag
Explorer

I have some events with message field as Bar Hello.., Bar Hi..., Bar Foo... and so on. I do not know beforehand how many this type of message are there. It is purely dynamical. But this messages are generated one at a time and timestamp of events with this messages are different. Now I want to show the search results as timechart. Right now I have this

index=baz host=server1 message="Bar*" | table host message _time | sort by -_time
Tags (3)
0 Karma

dcharboneau_spl
Splunk Employee
Splunk Employee

You should just need the timechart command.

See Below:

index=baz host=server1 message="Bar*" |timechart count(message) by message usenull=f useother=f

anirban_nag
Explorer

It would be good if in the graph it is a single line with different color for different type of message.

0 Karma

dcharboneau_spl
Splunk Employee
Splunk Employee

Not sure how that would work. A single line for x number of message types won't work as a visualization. you could do a Stacked column Chart view instead of a line chart. Above should produce multiple lines each a different color and one line for each message type over time.

cmccormick
Explorer

Are you wanting to know how many of the messages you are receiving for a given timeframe?

0 Karma

anirban_nag
Explorer

No I don't want to know how many but I want to create a line chart based on the messages and their frequency. Though I think I got close to it index=baz host=server1 message="Bar*" | table host message _time | sort by -_time | timechart span=2m count by message usenull=f. Now it would be good if in the graph it is a single line with different color for different type of message.

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...

Major Splunk Upgrade – Prepare your Environment for Splunk 10 Now!

Attention App Developers: Test Your Apps with the Splunk 10.0 Beta and Ensure Compatibility Before the ...

Stay Connected: Your Guide to June Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...