Splunk Search

How to use timechart in 3 directions?

SquarePeg
Engager

Hi all

I know that other people have asked similar questions but I have had no success in replicating their use cases. I am trying to display a timechart with lines showing sales for multiple stores, broken down by region and then city.

For example, Region A, has Cities A, B and C, Region B also has Cities A, B and C but inside each of those cities, there are between 2 and 5 stores. So when we click on a selector at the top, to select Region A for example, I need to show a trellis, broken out by city, showing a timechart with lines representing the sales for each store over the past say 6 months.

Hopefully I am explaining this well enough

Thanks

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SquarePeg,

you cannot put two fields in the BY clause of timechart.

But you can use the bin command to discretize _time bins and then use a stats count BY _time and the other keys:

<your_search>
| bin _time span=1h
| stats count BY _time key1 key2

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...