Splunk Search

How to overlay or mark a chart based on column value?

datamine
Loves-to-Learn Lots

Hi all,

I have a chart displaying 3 line charts based on our test results. Now we would like to show the test start and end timings like a marker on the _time in the x - axis like a vertical marker or something like that saying when the test has been started and ended.

alt text

Here is my second search:

index=gc sourcetype=gc_analysis  |table _time test_status |where test_status!="null"

Is it possible to mark the above chart with the field test_status marking the x - axis when the test has been started and ended.

Thanks,
Devon

0 Karma

woodcock
Esteemed Legend

Yes, this is a relatively new feature called Event Annotations:
https://docs.splunk.com/Documentation/Splunk/latest/Viz/ChartEventAnnotations

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...