Splunk Search

Is it possible to set a variable as the x-axis in a table?

kinda
Engager

Hello,

I don't specifically have anything down yet, I was just wondering if it would be possible to set a variable as the top row (x axis), the x axis would be auto populated by a variable.

Thanks in advance!

0 Karma
1 Solution

woodcock
Esteemed Legend

Yes, this is possible and very easy. You just use the chart (or timechart ) command instead of the stats command; see here:

https://answers.splunk.com/answers/32001/difference-between-stats-and-chart.html

View solution in original post

0 Karma

woodcock
Esteemed Legend

Yes, this is possible and very easy. You just use the chart (or timechart ) command instead of the stats command; see here:

https://answers.splunk.com/answers/32001/difference-between-stats-and-chart.html

0 Karma

kinda
Engager

Thats awesome! Thank you. I've never heard of/used the chart command. Thank you for your help!

0 Karma

woodcock
Esteemed Legend

See also xyseries (and it's opposite, untable ).

0 Karma

woodcock
Esteemed Legend

If in a dashboard, you create a control where the users selects from a list and this selection sets a token that the searches inside of the panels can reference. Is this what you mean?

0 Karma

kinda
Engager

A little,

I'm trying to get the x axis populated automatically with preset metadata that's available in my dashboard.

0 Karma

woodcock
Esteemed Legend

Start with this app:
https://splunkbase.splunk.com/app/1603/

I can help more if you can be much more specific.

0 Karma

kinda
Engager

I don't know if this is specific enough,

I have meta.hardware that has a list of devices. I would like to list those devices labeled in meta.hardware on the x axis without the need for hard coding those specific devices.

0 Karma

kinda
Engager

I don't know if this is important, but meta.hardware is listed as an 'interesting field', I don't know if I could somehow use that to my advantage

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...