Splunk Search

How to plot multiple datasets on the same chart?

GaryZ
Path Finder
I'm trying to implement a chart, so users can select their options from a multi-select input box, and automatically update the chart with the selection the user chose (1 to many).
 
 
 
index=abc dict1
| rename dict1.hardware as hardware, dict1.build as build,
| eval mv=mvappend(“process1", "process2", "process3")
| foreach mode=multivalue mv
     [rename dict1.<<FIELD>>.duration as duration
      | chart avg(duration) OVER build BY hardware
]
 
 
1) Can I have this done in one chart?
2) Can I also have an option to dynamically create multiple charts?
 
TIA.
 
Labels (3)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Please explain your raw data (best with illustration, anonymize as needed) and your desired output with illustration, then any logic to relate data to desired output if it is not painfully obvious.  I'm pretty sure things are possible.  But it is unfair to expect volunteers to speculate these things because different hypotheses can lead to vastly different paths.

0 Karma
Get Updates on the Splunk Community!

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...