Splunk Search

How to view only one data in graph when there is a list ?

R_Ramanan
Loves-to-Learn

I have list of items plotted in line graph which is basically time-series data. I would like to have an option to select one or multiple items alone from that list and see the graph

 

Like in below graph has two items listed in time series graph. How I can view only one item or multiple item when there are more items ? 

Can i add a search for the list of items on the right along with the list ?

 

R_Ramanan_0-1648102651339.png

 

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You can create a multi-select dropdown with the options and use that token to filter the results of your search so that only the selected series are left in events to be displayed in the chart.

0 Karma

R_Ramanan
Loves-to-Learn

Can we not directly select from the list on the right side rather than filter ?

When we move our mouse over the list, it is highlights and even on click shows just one item but once we move our mouse away, it again list all items & the graph for all items

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could use drilldown - the series name from the legend will be in $click.name2$ - if you then use that to filter the search, you would end up with one series i.e. multiple series would no longer be available. However, you might be able to reverse the logic so that when you click on the legend it removes that series from the chart/search - of course you need a way to reset, so perhaps clicking on the main chart area would restore all the series? Or perhaps if you want to get really creative, you could restore just the last one that was removed! 😁

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...