Splunk Search

How to overlay or mark a chart based on column value?

datamine
Loves-to-Learn Lots

Hi all,

I have a chart displaying 3 line charts based on our test results. Now we would like to show the test start and end timings like a marker on the _time in the x - axis like a vertical marker or something like that saying when the test has been started and ended.

alt text

Here is my second search:

index=gc sourcetype=gc_analysis  |table _time test_status |where test_status!="null"

Is it possible to mark the above chart with the field test_status marking the x - axis when the test has been started and ended.

Thanks,
Devon

0 Karma

woodcock
Esteemed Legend

Yes, this is a relatively new feature called Event Annotations:
https://docs.splunk.com/Documentation/Splunk/latest/Viz/ChartEventAnnotations

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...