I have a graph that I'm displaying as a 100% stacked column chart. Even though the Y-Axis is set to 0-100 I still see just the raw/absolute values when I mouse over the colored sections of the columns. Is there a way to make Splunk show the raw/absolute value and the percentage, like it does with the pie chart?
I've been able to get around this in one of my searches by using the "appendcols" command and then taking the percent of one column compared to both added together, but I'm not positive that method will work very well when I have more than 2 series.
You can use the
foreach command to calculate the percentage for each column iteratively.
In my example, I'm creating a timechart counting different values of my variable
view_version, and formatting the results as a percentage in a 100 Percent Stacked column chart.
base_search | timechart count by view_version | addtotals fieldname=_Total | foreach * [eval <<FIELD>> = '<<FIELD>>' * 100 / _Total] | fields - _Total
fields command removes the
_Total field from the final table.