Splunk Search

Is it possible to set a variable as the x-axis in a table?

kinda
Engager

Hello,

I don't specifically have anything down yet, I was just wondering if it would be possible to set a variable as the top row (x axis), the x axis would be auto populated by a variable.

Thanks in advance!

0 Karma
1 Solution

woodcock
Esteemed Legend

Yes, this is possible and very easy. You just use the chart (or timechart ) command instead of the stats command; see here:

https://answers.splunk.com/answers/32001/difference-between-stats-and-chart.html

View solution in original post

0 Karma

woodcock
Esteemed Legend

Yes, this is possible and very easy. You just use the chart (or timechart ) command instead of the stats command; see here:

https://answers.splunk.com/answers/32001/difference-between-stats-and-chart.html

0 Karma

kinda
Engager

Thats awesome! Thank you. I've never heard of/used the chart command. Thank you for your help!

0 Karma

woodcock
Esteemed Legend

See also xyseries (and it's opposite, untable ).

0 Karma

woodcock
Esteemed Legend

If in a dashboard, you create a control where the users selects from a list and this selection sets a token that the searches inside of the panels can reference. Is this what you mean?

0 Karma

kinda
Engager

A little,

I'm trying to get the x axis populated automatically with preset metadata that's available in my dashboard.

0 Karma

woodcock
Esteemed Legend

Start with this app:
https://splunkbase.splunk.com/app/1603/

I can help more if you can be much more specific.

0 Karma

kinda
Engager

I don't know if this is specific enough,

I have meta.hardware that has a list of devices. I would like to list those devices labeled in meta.hardware on the x axis without the need for hard coding those specific devices.

0 Karma

kinda
Engager

I don't know if this is important, but meta.hardware is listed as an 'interesting field', I don't know if I could somehow use that to my advantage

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...