Splunk Search

How to modify my search to get result shown in a visualization chart?

surekhasplunk
Communicator

Am using this search

index=level3 host=Test | chart count over "Opened" by "Assignment group"

I am getting the desired result in statistics but not in visualization.
Please help.
Am not able to post any pictures so pls mail me i will reply back.

Tags (2)
0 Karma

sundareshr
Legend

Which visualization are you using? Have you set it to one of the chart types (bar, line, area) or a format that is compatible with the data?

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Please try..capital over and by.

index=level3 host=Test | chart count OVER "Opened" BY "Assignment group"

your mail id is not available on your profile ..

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...