Splunk Search

How to use timechart in 3 directions?

SquarePeg
Engager

Hi all

I know that other people have asked similar questions but I have had no success in replicating their use cases. I am trying to display a timechart with lines showing sales for multiple stores, broken down by region and then city.

For example, Region A, has Cities A, B and C, Region B also has Cities A, B and C but inside each of those cities, there are between 2 and 5 stores. So when we click on a selector at the top, to select Region A for example, I need to show a trellis, broken out by city, showing a timechart with lines representing the sales for each store over the past say 6 months.

Hopefully I am explaining this well enough

Thanks

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SquarePeg,

you cannot put two fields in the BY clause of timechart.

But you can use the bin command to discretize _time bins and then use a stats count BY _time and the other keys:

<your_search>
| bin _time span=1h
| stats count BY _time key1 key2

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...