Splunk Search

Search Syntax graph: Two dimensional single measurement chart

gunderjt
Explorer

Sorry to bother everyone with what may end up being a very simple question but I've been pulling out my hair trying to figure out the syntax on this.

Suppose each event has two fields: ID and Action

ID,Action

1,Inject

1,Inject

1,Retrieve

2,Serve

3,Inject

....and so on.

I would like to know how to create a graph that looks a little like this shoddily made paint image.

Obviously the colors, positions, and labels don't matter I'm just interested in the syntax that can create a similar graph so I can tweak it from there.

Any help whatsoever would be greatly appreciated,

JTG

Tags (3)
0 Karma
1 Solution

eashwar
Communicator

Hello brother,

use the below search command and the chart formatting options,

| chart count over ID by Action

as a result of this you will get a table view, you have to do the charting stuff manually and save it.

go to the chart formatting options,
Chart type is BAR

then you have to select stacked mode

Stack mode is 100% STACKED

happy splunking brother,

if this helped you dont forget to vote,

yours,

eashwar raghunathan

View solution in original post

eashwar
Communicator

Hello brother,

use the below search command and the chart formatting options,

| chart count over ID by Action

as a result of this you will get a table view, you have to do the charting stuff manually and save it.

go to the chart formatting options,
Chart type is BAR

then you have to select stacked mode

Stack mode is 100% STACKED

happy splunking brother,

if this helped you dont forget to vote,

yours,

eashwar raghunathan

gunderjt
Explorer

That did it! Thanks a lot

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...