Splunk Search

Scatter Plot of some data

Contributor

I'm new to Splunk and trying to create graphs on some information that I'm collecting. I have lots of jobs that run everyday and provide the data below after they run. I would like to create a scatter point graph that is a timechart of resourcesused.ncpus for a 24H period. I would also like to create a scatter point graph of resourcesused.ncpus and resources_used.walltime.

10/04/2013 08:29:20;0010;somehost;Job;131091.somehost;Exitstatus=0 resourcesused.cpupercent=93 resourcesused.cput=00:01:42 resourcesused.mem=7284kb resourcesused.ncpus=33 resourcesused.vmem=57556kb resources_used.walltime=00:34:41

Can someone point me in the right direction? I can't figure out how to get the datapoints into the graph.

Thank you in advance.
Todd

0 Karma

Splunk Employee
Splunk Employee

For your timechart, this should do the trick, you can control the time range using the time range picker in the UI:

index=yourindex sourcetype=yoursourcetype ... | timechart avg(resourcesused.ncpus) as "resourcesused.ncpus"

For the scatter chart, try this:

index=yourindex sourcetype=yoursourcetype ... | table resourcesused.ncpus resourcesused.walltime

Contributor

I think I understand. Thank you again.

0 Karma

Contributor

Is there possibility to change the shape of scatter plot. I am getting rectangle , i need bubble .
Is there possibility to change the size of rectangle in graph.

0 Karma

Contributor

Any other suggestions?

0 Karma

SplunkTrust
SplunkTrust

Try below search

index=yourindex sourcetype=yoursourcetype...| timechart span=1d max(resourcesused.ncpus) as "resourcesused.ncpus"

If you are using a dashboard, select the chart type as scatter.

Contributor

The scatter option is greyed out. I can't seem to format the output in a way that scatter can be used.

0 Karma