Splunk Search

Split trellis over two variables



Can I separate Trellis visualization by two variables as keys? In other words, I would like a timechart for each combination of the two variables.

(variable2_1 for example is an instance in variable2 column)

My goal is to have:



For now I succeeded either doing: 

| stats max(variable1) by variable2, variable3



| stats max(variable1) by variable2, variable3



and the output (one of the Trellis for example):

Screen Shot 2021-05-10 at 11.56.46.png

But I wanted a timechart and a separate histogram for each combination of variable 2 and 3.

I also tried:



| timechart max(variable1) by variable2, variable3 



which doesn't work.

Could you kindly assist? the aggregation section in Trellis also doesn't seem to produce the wanted results. 


Labels (1)
0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!