Splunk Search

Need chart for two values

edrad80
New Member

Hi

I have a basic XML file returning, Date-time value and a value in seconds see example("GmtDateTime":"2013-08-14 01:15:26","TotalSeconds":15.593). There is one value every 30 minutes. I need to have a column chart showing x - date-time and Y - TotalSeconds.

I have tried a lot of different options today but can never get it showing correctly.
Just need a pointer in the correct direction

Tags (2)
0 Karma

edrad80
New Member

It almost works, the GmtDateTime is correct but it shows the average TotalSeconds for all instances instead of the correct total

0 Karma

linu1988
Champion

Provided you are having the fields correctly extracted, you can have |Timechart avg(TotalSeconds) OR Chart avg(TotalSeconds) by GmtDateTime.

Just a table GmtDateTime,TotalSeconds. where your primary axis should be GmtDateTime and TotalSeconds can be secondary axis in module for dashboard

|Timechart span=30m  avg(TotalSeconds)

I have updated the answer, hope it works.

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...