Splunk Search

How to overlay or mark a chart based on column value?

datamine
Loves-to-Learn Lots

Hi all,

I have a chart displaying 3 line charts based on our test results. Now we would like to show the test start and end timings like a marker on the _time in the x - axis like a vertical marker or something like that saying when the test has been started and ended.

alt text

Here is my second search:

index=gc sourcetype=gc_analysis  |table _time test_status |where test_status!="null"

Is it possible to mark the above chart with the field test_status marking the x - axis when the test has been started and ended.

Thanks,
Devon

0 Karma

woodcock
Esteemed Legend

Yes, this is a relatively new feature called Event Annotations:
https://docs.splunk.com/Documentation/Splunk/latest/Viz/ChartEventAnnotations

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...