Splunk Search

Plot time series chart based on values selected where in value can single or multiple

R_Ramanan
Loves-to-Learn

I am using query as below 

index="test" sourcetype="reports"
| bin _time span=1m | stats values(a) as a values(b) as b values(c) as c values(d) as d values(e) as e values(f) as f values(g) as g by par1, _time
| append [search (index="test" sourcetype=reports_metadata) | table par1,par2,par3,par4,par5,par6,par7,par8,par9,par10,par11,par12]
| eventstats values(par2) as par2,values(par3) as par3, values(par4) as par4, values(par5) as par5, values(par6) as par6, values(par7) as par7, values(par8) as par8,values(par9) as par9,values(par10) as par10,values(par11) as par11,values(par12) as par12, values(a) as a alues(b) as b values(c) as c values(d) as d values(e) as e values(f) as f values(g) as g by par1
| search par2 IN ("*") par3 IN ("*") par3 IN ("*") par4 ("*") par5 IN ("*") par6 IN ("*") par7 IN ("*") par8 IN ("*") par9 IN ("*") par10 IN ("*")
| search par1="*"ar2 IN ("*") par3 IN ("*") par3 IN ("*") par4 ("*") par5 IN ("*") par6 IN ("*") par7 IN ("*") par8 IN ("*") par9 IN ("*") par10 IN ("*") par11 IN ("*") par12 IN ("*")
| timechart span=15m values(a) by par1 limit=0

In this query, I am able to use any values rangin from a to g and plot a time series graph.

I need help in plotting time series for one or more values and also how this value can be used to pick from a drop down filter 

#timeseries #timechart #xyseries #multiseries #multivalue 

Labels (1)
0 Karma

R_Ramanan
Loves-to-Learn

Report data would be as below

par1timebefglmnrs
SNC112/5/2024 16:30299367-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9312.91
SNC112/5/2024 16:45299364-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9512.87
SNC112/5/2024 17:00299369-7.7-7.9-7.71.00E-371.00E-371.90E-0713.8912.88
SNC112/5/2024 17:15299364-7.6-7.9-7.71.00E-371.00E-371.80E-0713.9212.89
SNC112/5/2024 17:30299368-7.6-7.9-7.71.00E-371.00E-371.90E-0713.8712.83
SNC112/5/2024 17:45299362-7.6-7.9-7.71.00E-371.00E-371.90E-0713.9212.78
SNC112/5/2024 18:00299368-7.6-7.9-7.71.00E-371.00E-371.80E-0713.9212.88
SNC112/5/2024 18:15299371-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9512.88
SNC112/5/2024 18:30299359-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9412.83
SNC112/5/2024 18:45299362-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9212.86
SNC112/5/2024 19:00299369-7.7-7.9-7.71.00E-371.00E-371.90E-0713.8912.85
SNC112/5/2024 19:15299365-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9212.89
SNC112/5/2024 19:30299368-7.6-7.9-7.71.00E-371.00E-371.80E-0713.912.75
SNC112/5/2024 19:45299369-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9212.85
SNC112/5/2024 20:00299363-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9312.89
SNC112/5/2024 20:15299358-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9312.85
SNC212/5/2024 16:30259482-7.6-6.9-7.69.00E-351.00E-340.00119.589.54
SNC212/5/2024 16:45259479-7.5-6.9-7.68.00E-351.00E-340.00119.599.53
SNC212/5/2024 17:00259478-7.5-6.9-7.68.00E-351.00E-340.00119.599.56
SNC212/5/2024 17:15259484-7.5-6.9-7.65.00E-351.00E-340.00119.619.55
SNC212/5/2024 17:30259487-7.6-6.9-7.66.00E-352.00E-340.00119.569.52
SNC212/5/2024 17:45259480-7.5-6.9-7.68.00E-351.00E-340.00119.579.53
0 Karma

R_Ramanan
Loves-to-Learn

Attached sample data of two tables.  for each SNC1, SNC2, there will be data for each 15 mins and values can be different. Now the idea is to do timeseries for each SNC any of the values and filtering will be mainly based on SNC and any of the values (one or more values at the same time )

0 Karma

R_Ramanan
Loves-to-Learn

reports_metadata file contains data as below

snc_labeldeployment_statepar1par2par3par4par5par6par7par8par9par10par11par12par13par14par15par16par17par18par19
SNC1discoveredL0CPC410037.5ABCMOTRABC-0101XYZ-01011-1-115-7-115.5 -23.697888133.879791  ABAA
SNC2discoveredNL0CPC420037.5DCEOTRDCE-0102CSNO-01017-8-110-2-215.515.5-30.296649153.113164-28.864117153.047084BBAB
SNC3discoveredL0CPC7430037.5XYZMOTRABC-0101PTMA-010115-7-115-7-115.515.5-30.296649153.113164-31.431357152.914377AAAD
SNC4discoveredNL0CPC6410037.5ABCMOTRDCE-0102BRDE-010215-7-110-2-215.515.5-27.357494153.022632-27.471961153.025407CCCA
SNC5discoveredL0CPC4420037.5ABBMOTRCZWX-0201HABC-010110-2-21-1-115.515.5-33.797823151.180644-33.896447151.193881DEDZ
0 Karma

tscroggins
Influencer

Hi @R_Ramanan,

Can you provide a small set of sample data? If a, b, c, ..., g are only related to par2, par3, par4, ..., par12 by par1, then par1 is likely your only filterable parameter.

0 Karma

R_Ramanan
Loves-to-Learn

@tscroggins, hope the information is helpful, please let me know if you need any additional details

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...