Splunk Search

How to view only one data in graph when there is a list ?

R_Ramanan
Loves-to-Learn

I have list of items plotted in line graph which is basically time-series data. I would like to have an option to select one or multiple items alone from that list and see the graph

 

Like in below graph has two items listed in time series graph. How I can view only one item or multiple item when there are more items ? 

Can i add a search for the list of items on the right along with the list ?

 

R_Ramanan_0-1648102651339.png

 

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You can create a multi-select dropdown with the options and use that token to filter the results of your search so that only the selected series are left in events to be displayed in the chart.

0 Karma

R_Ramanan
Loves-to-Learn

Can we not directly select from the list on the right side rather than filter ?

When we move our mouse over the list, it is highlights and even on click shows just one item but once we move our mouse away, it again list all items & the graph for all items

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could use drilldown - the series name from the legend will be in $click.name2$ - if you then use that to filter the search, you would end up with one series i.e. multiple series would no longer be available. However, you might be able to reverse the logic so that when you click on the legend it removes that series from the chart/search - of course you need a way to reset, so perhaps clicking on the main chart area would restore all the series? Or perhaps if you want to get really creative, you could restore just the last one that was removed! 😁

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...