Splunk Search

Split trellis over two variables

yifatcy
Explorer

Hi,

Can I separate Trellis visualization by two variables as keys? In other words, I would like a timechart for each combination of the two variables.

(variable2_1 for example is an instance in variable2 column)

My goal is to have:

goal.png

 

For now I succeeded either doing: 

| stats max(variable1) by variable2, variable3

 

 

| stats max(variable1) by variable2, variable3

 

 

and the output (one of the Trellis for example):

Screen Shot 2021-05-10 at 11.56.46.png

But I wanted a timechart and a separate histogram for each combination of variable 2 and 3.

I also tried:

 

 

| timechart max(variable1) by variable2, variable3 

 

 

which doesn't work.

Could you kindly assist? the aggregation section in Trellis also doesn't seem to produce the wanted results. 

Thanks.

Labels (1)
0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!