Splunk Search

How to overlay a single static line against a timechart with multiple series without displaying each series as its own line?

burras
Communicator

I have what should be a fairly simple timechart that I'm looking to do.

In our data, we have a field (util) that represents percent utilization at each of 3 sites. The sites are configured for (n+1) capacity so we want to have a manually entered capacity line at 66% (to show where if we had a site failure we'd still be able to maintain service on the 2 other sites). The general way I'd chart this without any sort of capacity line is |timechart max(util) by site. To add in the capacity line we'd generally do |eval capacity=66 |timechart max(util),capacity by site. However, when we do this, we end up with 3 separate capacity notations on the time chart: capacity:site1, capacity:site2, capacity:site3. And while we can pick all 3 as overlays so they show a single line, they still show as 3 separate notations in the legend.

What's the best way to overlay a single static line against a timechart with multiple series without showing as a per series result?

1 Solution

gokadroid
Motivator

If the capacity=66 and max(util) are of same unit and can be plotted in same graph then can you try to add your eval command after timechart:

|timechart max(util) by site | eval capactity=66

That should keep one line of 66 on the timechart with all others the way you want.

View solution in original post

gokadroid
Motivator

If the capacity=66 and max(util) are of same unit and can be plotted in same graph then can you try to add your eval command after timechart:

|timechart max(util) by site | eval capactity=66

That should keep one line of 66 on the timechart with all others the way you want.

burras
Communicator

Worked perfectly - thanks!

gcusello
SplunkTrust
SplunkTrust

Hi burras,
I'm out so I cannot use my pc.
Every way, you can see the License usage Report to configure your overlay.
If you need Tomorrow morning I'll be again at work.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...