Splunk Search

No Visualisation although enough values

ToniSchulz
Explorer

Hello everyone,

I have a strange problem. I want to visualize two different temperatures over the time and wrote the following search query:

index=1_Scheibenkleben sourcetype=1_Scheibenkleben_csv Raumtemperatur=* OR Scheibentemperatur=*|chart list(Raumtemperatur) as RT, list(Scheibentemperatur) as ST over _time span=1d

The table that I get looks like this:

_time                       RT                                   ST
2015-01-01                  17,6
                            16,5
                            16,6
2015-01-02                  16,8                                22,6
                            16,9                                20,6
                                                                21
                            17                                  18
2015-01-03        etc.....  

For this combination I don´t get a visualisation to work. The values in the chart are 0 although they are listed further down. When I directly use the chart command the same happens. It seems that the problem is, that for some time stamps the value for e.g. Scheibentemperatur ist 0 although the =* command. We used that command because some entrys don´t have values and this made us sure to not have too many of them. I also tried different spans and different time ranges, but no results.

Does anyone have an idea why that is?

Thanks a lot in advance!

ToniSchulz
Explorer

Hi stephanefotso,

thanks for your answer! I tried that out, unfortunatly it did not change anything.
Could there be other reasons?

0 Karma

stephanefotso
Motivator

I think your query need parenthesis. try this:

index=1_Scheibenkleben sourcetype=1_Scheibenkleben_csv  (Raumtemperatur=* OR Scheibentemperatur=*)|chart list(Raumtemperatur) as RT, list(Scheibentemperatur) as ST over _time span=1d
SGF
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...