Splunk Search

Search Syntax graph: Two dimensional single measurement chart

gunderjt
Explorer

Sorry to bother everyone with what may end up being a very simple question but I've been pulling out my hair trying to figure out the syntax on this.

Suppose each event has two fields: ID and Action

ID,Action

1,Inject

1,Inject

1,Retrieve

2,Serve

3,Inject

....and so on.

I would like to know how to create a graph that looks a little like this shoddily made paint image.

Obviously the colors, positions, and labels don't matter I'm just interested in the syntax that can create a similar graph so I can tweak it from there.

Any help whatsoever would be greatly appreciated,

JTG

Tags (3)
0 Karma
1 Solution

eashwar
Communicator

Hello brother,

use the below search command and the chart formatting options,

| chart count over ID by Action

as a result of this you will get a table view, you have to do the charting stuff manually and save it.

go to the chart formatting options,
Chart type is BAR

then you have to select stacked mode

Stack mode is 100% STACKED

happy splunking brother,

if this helped you dont forget to vote,

yours,

eashwar raghunathan

View solution in original post

eashwar
Communicator

Hello brother,

use the below search command and the chart formatting options,

| chart count over ID by Action

as a result of this you will get a table view, you have to do the charting stuff manually and save it.

go to the chart formatting options,
Chart type is BAR

then you have to select stacked mode

Stack mode is 100% STACKED

happy splunking brother,

if this helped you dont forget to vote,

yours,

eashwar raghunathan

gunderjt
Explorer

That did it! Thanks a lot

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...