Splunk Search

Line Chart single value over time

Blackninja5431
New Member

I have a log containing memory usage over a period of time. How can I plot a line graph where the x-axis is the time, and the y-axis is the amount of memory used at that time.

Tags (1)
0 Karma
1 Solution

Ayn
Legend

If you want to grab each data point, just using table with the fields _time and your field containing the memory info will do. Let's say the field is called memory_used:

... | table _time memory_used

After that, choose the chart view and apply the appropriate settings.

If you have loads of data points there is a risk of overwhelming the chart module with more points than it can handle. In that case, use timechart and some kind of statistical function for representing values in a certain time interval, like first, max or avg. You need to supply some kind of statistical function because timechart divides the events into discrete sets of time intervals, and it needs to know how to handle if there is more than 1 event in an interval.

... | timechart avg(memory_used)

View solution in original post

0 Karma

Ayn
Legend

If you want to grab each data point, just using table with the fields _time and your field containing the memory info will do. Let's say the field is called memory_used:

... | table _time memory_used

After that, choose the chart view and apply the appropriate settings.

If you have loads of data points there is a risk of overwhelming the chart module with more points than it can handle. In that case, use timechart and some kind of statistical function for representing values in a certain time interval, like first, max or avg. You need to supply some kind of statistical function because timechart divides the events into discrete sets of time intervals, and it needs to know how to handle if there is more than 1 event in an interval.

... | timechart avg(memory_used)
0 Karma

sam_jacob
Path Finder

After tabulating the data, what settings do you use for chart? I have the table needed to chart by two different fields, but how do I chart Field A by Field B?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...