Splunk Search

Plot time series chart based on values selected where in value can single or multiple

R_Ramanan
Loves-to-Learn

I am using query as below 

index="test" sourcetype="reports"
| bin _time span=1m | stats values(a) as a values(b) as b values(c) as c values(d) as d values(e) as e values(f) as f values(g) as g by par1, _time
| append [search (index="test" sourcetype=reports_metadata) | table par1,par2,par3,par4,par5,par6,par7,par8,par9,par10,par11,par12]
| eventstats values(par2) as par2,values(par3) as par3, values(par4) as par4, values(par5) as par5, values(par6) as par6, values(par7) as par7, values(par8) as par8,values(par9) as par9,values(par10) as par10,values(par11) as par11,values(par12) as par12, values(a) as a alues(b) as b values(c) as c values(d) as d values(e) as e values(f) as f values(g) as g by par1
| search par2 IN ("*") par3 IN ("*") par3 IN ("*") par4 ("*") par5 IN ("*") par6 IN ("*") par7 IN ("*") par8 IN ("*") par9 IN ("*") par10 IN ("*")
| search par1="*"ar2 IN ("*") par3 IN ("*") par3 IN ("*") par4 ("*") par5 IN ("*") par6 IN ("*") par7 IN ("*") par8 IN ("*") par9 IN ("*") par10 IN ("*") par11 IN ("*") par12 IN ("*")
| timechart span=15m values(a) by par1 limit=0

In this query, I am able to use any values rangin from a to g and plot a time series graph.

I need help in plotting time series for one or more values and also how this value can be used to pick from a drop down filter 

#timeseries #timechart #xyseries #multiseries #multivalue 

Labels (1)
0 Karma

R_Ramanan
Loves-to-Learn

Report data would be as below

par1timebefglmnrs
SNC112/5/2024 16:30299367-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9312.91
SNC112/5/2024 16:45299364-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9512.87
SNC112/5/2024 17:00299369-7.7-7.9-7.71.00E-371.00E-371.90E-0713.8912.88
SNC112/5/2024 17:15299364-7.6-7.9-7.71.00E-371.00E-371.80E-0713.9212.89
SNC112/5/2024 17:30299368-7.6-7.9-7.71.00E-371.00E-371.90E-0713.8712.83
SNC112/5/2024 17:45299362-7.6-7.9-7.71.00E-371.00E-371.90E-0713.9212.78
SNC112/5/2024 18:00299368-7.6-7.9-7.71.00E-371.00E-371.80E-0713.9212.88
SNC112/5/2024 18:15299371-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9512.88
SNC112/5/2024 18:30299359-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9412.83
SNC112/5/2024 18:45299362-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9212.86
SNC112/5/2024 19:00299369-7.7-7.9-7.71.00E-371.00E-371.90E-0713.8912.85
SNC112/5/2024 19:15299365-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9212.89
SNC112/5/2024 19:30299368-7.6-7.9-7.71.00E-371.00E-371.80E-0713.912.75
SNC112/5/2024 19:45299369-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9212.85
SNC112/5/2024 20:00299363-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9312.89
SNC112/5/2024 20:15299358-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9312.85
SNC212/5/2024 16:30259482-7.6-6.9-7.69.00E-351.00E-340.00119.589.54
SNC212/5/2024 16:45259479-7.5-6.9-7.68.00E-351.00E-340.00119.599.53
SNC212/5/2024 17:00259478-7.5-6.9-7.68.00E-351.00E-340.00119.599.56
SNC212/5/2024 17:15259484-7.5-6.9-7.65.00E-351.00E-340.00119.619.55
SNC212/5/2024 17:30259487-7.6-6.9-7.66.00E-352.00E-340.00119.569.52
SNC212/5/2024 17:45259480-7.5-6.9-7.68.00E-351.00E-340.00119.579.53
0 Karma

R_Ramanan
Loves-to-Learn

Attached sample data of two tables.  for each SNC1, SNC2, there will be data for each 15 mins and values can be different. Now the idea is to do timeseries for each SNC any of the values and filtering will be mainly based on SNC and any of the values (one or more values at the same time )

0 Karma

R_Ramanan
Loves-to-Learn

reports_metadata file contains data as below

snc_labeldeployment_statepar1par2par3par4par5par6par7par8par9par10par11par12par13par14par15par16par17par18par19
SNC1discoveredL0CPC410037.5ABCMOTRABC-0101XYZ-01011-1-115-7-115.5 -23.697888133.879791  ABAA
SNC2discoveredNL0CPC420037.5DCEOTRDCE-0102CSNO-01017-8-110-2-215.515.5-30.296649153.113164-28.864117153.047084BBAB
SNC3discoveredL0CPC7430037.5XYZMOTRABC-0101PTMA-010115-7-115-7-115.515.5-30.296649153.113164-31.431357152.914377AAAD
SNC4discoveredNL0CPC6410037.5ABCMOTRDCE-0102BRDE-010215-7-110-2-215.515.5-27.357494153.022632-27.471961153.025407CCCA
SNC5discoveredL0CPC4420037.5ABBMOTRCZWX-0201HABC-010110-2-21-1-115.515.5-33.797823151.180644-33.896447151.193881DEDZ
0 Karma

tscroggins
Influencer

Hi @R_Ramanan,

Can you provide a small set of sample data? If a, b, c, ..., g are only related to par2, par3, par4, ..., par12 by par1, then par1 is likely your only filterable parameter.

0 Karma

R_Ramanan
Loves-to-Learn

@tscroggins, hope the information is helpful, please let me know if you need any additional details

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...