Splunk Search

Search Syntax graph: Two dimensional single measurement chart

gunderjt
Explorer

Sorry to bother everyone with what may end up being a very simple question but I've been pulling out my hair trying to figure out the syntax on this.

Suppose each event has two fields: ID and Action

ID,Action

1,Inject

1,Inject

1,Retrieve

2,Serve

3,Inject

....and so on.

I would like to know how to create a graph that looks a little like this shoddily made paint image.

Obviously the colors, positions, and labels don't matter I'm just interested in the syntax that can create a similar graph so I can tweak it from there.

Any help whatsoever would be greatly appreciated,

JTG

Tags (3)
0 Karma
1 Solution

eashwar
Communicator

Hello brother,

use the below search command and the chart formatting options,

| chart count over ID by Action

as a result of this you will get a table view, you have to do the charting stuff manually and save it.

go to the chart formatting options,
Chart type is BAR

then you have to select stacked mode

Stack mode is 100% STACKED

happy splunking brother,

if this helped you dont forget to vote,

yours,

eashwar raghunathan

View solution in original post

eashwar
Communicator

Hello brother,

use the below search command and the chart formatting options,

| chart count over ID by Action

as a result of this you will get a table view, you have to do the charting stuff manually and save it.

go to the chart formatting options,
Chart type is BAR

then you have to select stacked mode

Stack mode is 100% STACKED

happy splunking brother,

if this helped you dont forget to vote,

yours,

eashwar raghunathan

gunderjt
Explorer

That did it! Thanks a lot

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...