Splunk Search

Line Chart single value over time

Blackninja5431
New Member

I have a log containing memory usage over a period of time. How can I plot a line graph where the x-axis is the time, and the y-axis is the amount of memory used at that time.

Tags (1)
0 Karma
1 Solution

Ayn
Legend

If you want to grab each data point, just using table with the fields _time and your field containing the memory info will do. Let's say the field is called memory_used:

... | table _time memory_used

After that, choose the chart view and apply the appropriate settings.

If you have loads of data points there is a risk of overwhelming the chart module with more points than it can handle. In that case, use timechart and some kind of statistical function for representing values in a certain time interval, like first, max or avg. You need to supply some kind of statistical function because timechart divides the events into discrete sets of time intervals, and it needs to know how to handle if there is more than 1 event in an interval.

... | timechart avg(memory_used)

View solution in original post

0 Karma

Ayn
Legend

If you want to grab each data point, just using table with the fields _time and your field containing the memory info will do. Let's say the field is called memory_used:

... | table _time memory_used

After that, choose the chart view and apply the appropriate settings.

If you have loads of data points there is a risk of overwhelming the chart module with more points than it can handle. In that case, use timechart and some kind of statistical function for representing values in a certain time interval, like first, max or avg. You need to supply some kind of statistical function because timechart divides the events into discrete sets of time intervals, and it needs to know how to handle if there is more than 1 event in an interval.

... | timechart avg(memory_used)
0 Karma

sam_jacob
Path Finder

After tabulating the data, what settings do you use for chart? I have the table needed to chart by two different fields, but how do I chart Field A by Field B?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Data Management Digest – June 2026

Welcome to the June 2026 edition of Data Management Digest! This month’s update is short and sweet, with a ...

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...