Splunk Search

Split trellis over two variables

yifatcy
Path Finder

Hi,

Can I separate Trellis visualization by two variables as keys? In other words, I would like a timechart for each combination of the two variables.

(variable2_1 for example is an instance in variable2 column)

My goal is to have:

goal.png

 

For now I succeeded either doing: 

| stats max(variable1) by variable2, variable3

 

 

| stats max(variable1) by variable2, variable3

 

 

and the output (one of the Trellis for example):

Screen Shot 2021-05-10 at 11.56.46.png

But I wanted a timechart and a separate histogram for each combination of variable 2 and 3.

I also tried:

 

 

| timechart max(variable1) by variable2, variable3 

 

 

which doesn't work.

Could you kindly assist? the aggregation section in Trellis also doesn't seem to produce the wanted results. 

Thanks.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Platform Highlights | November 2022 Newsletter

 November 2022 Skill Up on Splunk with our New Builder Tech Talk SeriesCan you build it? Yes you can! *play ...

Splunk Education - Fast Start Program!

Welcome to Splunk Education! Splunk training programs are designed to enable you to get started quickly and ...

Five Subtly Different Ways of Adding Manual Instrumentation in Java

You can find the code of this example on GitHub here. Please feel free to star the repository to keep in ...