Splunk Search

How to rename timechart legend static names with variable names

wti
Engager

Hello,
I have a timechart search (search code snippet below), everything works great.
The chart shows up and the legend shows "sample1", "sample2" .

What I would like to do is, Instead these of the static names I would like to put in a variable name, for example, $location$, but when I put $location$ in replacing sample2 I get the literal text "$location$" in my legend, sorry for such a newbie question but we are muddling our way through.

 | search siteid=$siteid$ location=$location$ 
| timechart avg("powerdata{}.sample1{}.current") assample1, avg("powerdata{}.sample2{}.current") as sample2 
| eval sample1=round(sample1,2) 
| eval sample2=round(sample2,2) 
0 Karma

vnravikumar
Champion

Hi

Check this

<dashboard>
  <label>timehart</label>
  <init>
    <set token="legend1">sample1_legend</set>
    <set token="legend2">sample2_legend</set>
  </init>
  <row>
    <panel>
      <chart>
        <search>
          <query>index=_internal 
| timechart eval(round(avg(date_second),2)) as $legend1$, eval(round(avg(date_hour),2)) as $legend2$</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
        <option name="charting.chart">line</option>
        <option name="charting.drilldown">none</option>
      </chart>
    </panel>
  </row>
</dashboard>
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...