Splunk Search

Line Chart single value over time

Blackninja5431
New Member

I have a log containing memory usage over a period of time. How can I plot a line graph where the x-axis is the time, and the y-axis is the amount of memory used at that time.

Tags (1)
0 Karma
1 Solution

Ayn
Legend

If you want to grab each data point, just using table with the fields _time and your field containing the memory info will do. Let's say the field is called memory_used:

... | table _time memory_used

After that, choose the chart view and apply the appropriate settings.

If you have loads of data points there is a risk of overwhelming the chart module with more points than it can handle. In that case, use timechart and some kind of statistical function for representing values in a certain time interval, like first, max or avg. You need to supply some kind of statistical function because timechart divides the events into discrete sets of time intervals, and it needs to know how to handle if there is more than 1 event in an interval.

... | timechart avg(memory_used)

View solution in original post

0 Karma

Ayn
Legend

If you want to grab each data point, just using table with the fields _time and your field containing the memory info will do. Let's say the field is called memory_used:

... | table _time memory_used

After that, choose the chart view and apply the appropriate settings.

If you have loads of data points there is a risk of overwhelming the chart module with more points than it can handle. In that case, use timechart and some kind of statistical function for representing values in a certain time interval, like first, max or avg. You need to supply some kind of statistical function because timechart divides the events into discrete sets of time intervals, and it needs to know how to handle if there is more than 1 event in an interval.

... | timechart avg(memory_used)
0 Karma

sam_jacob
Path Finder

After tabulating the data, what settings do you use for chart? I have the table needed to chart by two different fields, but how do I chart Field A by Field B?

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...