Splunk Search

How to use timechart in 3 directions?

SquarePeg
Engager

Hi all

I know that other people have asked similar questions but I have had no success in replicating their use cases. I am trying to display a timechart with lines showing sales for multiple stores, broken down by region and then city.

For example, Region A, has Cities A, B and C, Region B also has Cities A, B and C but inside each of those cities, there are between 2 and 5 stores. So when we click on a selector at the top, to select Region A for example, I need to show a trellis, broken out by city, showing a timechart with lines representing the sales for each store over the past say 6 months.

Hopefully I am explaining this well enough

Thanks

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SquarePeg,

you cannot put two fields in the BY clause of timechart.

But you can use the bin command to discretize _time bins and then use a stats count BY _time and the other keys:

<your_search>
| bin _time span=1h
| stats count BY _time key1 key2

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...