Splunk Search

How to order the bars within each time segment of a timechart (bar style) by the sum of the field from largest to smallest?

antonyhan
Path Finder

I am trying to order the bars within each time segment from largest to smallest?
is there a way of doing it?

0 Karma

meenal901
Communicator

timechart will not be able to do this. Just plain stats would help you with ordering based on values, but will not have _time in this case:

sourcetype=test2| stats sum(Count) as Count by Name| sort - Count

Data:
Name,Count
A,100
B,1000
C,10

0 Karma

emiller42
Motivator

This may not be helpful, but I would strongly advise against doing this. Having the bars potentially change order with every time-slice would make the overall presentation confusing and difficult to parse.

antonyhan
Path Finder

you got a point! it's a customer request and I couldn't figure out a solution.
is there a way to do with just regular chart?

0 Karma

somesoni2
Revered Legend

Could you explain more about expected output by some sample values?

0 Karma

antonyhan
Path Finder

say with in 5 mins we have A100, B 1000, C 50. right now plain vanilla timechart with bar will order by legend name. Instead of the order of A B C, we would like to see an order of BAC from top to bottom as B has the largest value. Hope this explains.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...