Splunk Search

Plot time series chart based on values selected where in value can single or multiple

R_Ramanan
Loves-to-Learn

I am using query as below 

index="test" sourcetype="reports"
| bin _time span=1m | stats values(a) as a values(b) as b values(c) as c values(d) as d values(e) as e values(f) as f values(g) as g by par1, _time
| append [search (index="test" sourcetype=reports_metadata) | table par1,par2,par3,par4,par5,par6,par7,par8,par9,par10,par11,par12]
| eventstats values(par2) as par2,values(par3) as par3, values(par4) as par4, values(par5) as par5, values(par6) as par6, values(par7) as par7, values(par8) as par8,values(par9) as par9,values(par10) as par10,values(par11) as par11,values(par12) as par12, values(a) as a alues(b) as b values(c) as c values(d) as d values(e) as e values(f) as f values(g) as g by par1
| search par2 IN ("*") par3 IN ("*") par3 IN ("*") par4 ("*") par5 IN ("*") par6 IN ("*") par7 IN ("*") par8 IN ("*") par9 IN ("*") par10 IN ("*")
| search par1="*"ar2 IN ("*") par3 IN ("*") par3 IN ("*") par4 ("*") par5 IN ("*") par6 IN ("*") par7 IN ("*") par8 IN ("*") par9 IN ("*") par10 IN ("*") par11 IN ("*") par12 IN ("*")
| timechart span=15m values(a) by par1 limit=0

In this query, I am able to use any values rangin from a to g and plot a time series graph.

I need help in plotting time series for one or more values and also how this value can be used to pick from a drop down filter 

#timeseries #timechart #xyseries #multiseries #multivalue 

Labels (1)
0 Karma

R_Ramanan
Loves-to-Learn

Report data would be as below

par1timebefglmnrs
SNC112/5/2024 16:30299367-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9312.91
SNC112/5/2024 16:45299364-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9512.87
SNC112/5/2024 17:00299369-7.7-7.9-7.71.00E-371.00E-371.90E-0713.8912.88
SNC112/5/2024 17:15299364-7.6-7.9-7.71.00E-371.00E-371.80E-0713.9212.89
SNC112/5/2024 17:30299368-7.6-7.9-7.71.00E-371.00E-371.90E-0713.8712.83
SNC112/5/2024 17:45299362-7.6-7.9-7.71.00E-371.00E-371.90E-0713.9212.78
SNC112/5/2024 18:00299368-7.6-7.9-7.71.00E-371.00E-371.80E-0713.9212.88
SNC112/5/2024 18:15299371-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9512.88
SNC112/5/2024 18:30299359-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9412.83
SNC112/5/2024 18:45299362-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9212.86
SNC112/5/2024 19:00299369-7.7-7.9-7.71.00E-371.00E-371.90E-0713.8912.85
SNC112/5/2024 19:15299365-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9212.89
SNC112/5/2024 19:30299368-7.6-7.9-7.71.00E-371.00E-371.80E-0713.912.75
SNC112/5/2024 19:45299369-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9212.85
SNC112/5/2024 20:00299363-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9312.89
SNC112/5/2024 20:15299358-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9312.85
SNC212/5/2024 16:30259482-7.6-6.9-7.69.00E-351.00E-340.00119.589.54
SNC212/5/2024 16:45259479-7.5-6.9-7.68.00E-351.00E-340.00119.599.53
SNC212/5/2024 17:00259478-7.5-6.9-7.68.00E-351.00E-340.00119.599.56
SNC212/5/2024 17:15259484-7.5-6.9-7.65.00E-351.00E-340.00119.619.55
SNC212/5/2024 17:30259487-7.6-6.9-7.66.00E-352.00E-340.00119.569.52
SNC212/5/2024 17:45259480-7.5-6.9-7.68.00E-351.00E-340.00119.579.53
0 Karma

R_Ramanan
Loves-to-Learn

Attached sample data of two tables.  for each SNC1, SNC2, there will be data for each 15 mins and values can be different. Now the idea is to do timeseries for each SNC any of the values and filtering will be mainly based on SNC and any of the values (one or more values at the same time )

0 Karma

R_Ramanan
Loves-to-Learn

reports_metadata file contains data as below

snc_labeldeployment_statepar1par2par3par4par5par6par7par8par9par10par11par12par13par14par15par16par17par18par19
SNC1discoveredL0CPC410037.5ABCMOTRABC-0101XYZ-01011-1-115-7-115.5 -23.697888133.879791  ABAA
SNC2discoveredNL0CPC420037.5DCEOTRDCE-0102CSNO-01017-8-110-2-215.515.5-30.296649153.113164-28.864117153.047084BBAB
SNC3discoveredL0CPC7430037.5XYZMOTRABC-0101PTMA-010115-7-115-7-115.515.5-30.296649153.113164-31.431357152.914377AAAD
SNC4discoveredNL0CPC6410037.5ABCMOTRDCE-0102BRDE-010215-7-110-2-215.515.5-27.357494153.022632-27.471961153.025407CCCA
SNC5discoveredL0CPC4420037.5ABBMOTRCZWX-0201HABC-010110-2-21-1-115.515.5-33.797823151.180644-33.896447151.193881DEDZ
0 Karma

tscroggins
Influencer

Hi @R_Ramanan,

Can you provide a small set of sample data? If a, b, c, ..., g are only related to par2, par3, par4, ..., par12 by par1, then par1 is likely your only filterable parameter.

0 Karma

R_Ramanan
Loves-to-Learn

@tscroggins, hope the information is helpful, please let me know if you need any additional details

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...