Splunk Search

Split trellis over two variables



Can I separate Trellis visualization by two variables as keys? In other words, I would like a timechart for each combination of the two variables.

(variable2_1 for example is an instance in variable2 column)

My goal is to have:



For now I succeeded either doing: 

| stats max(variable1) by variable2, variable3



| stats max(variable1) by variable2, variable3



and the output (one of the Trellis for example):

Screen Shot 2021-05-10 at 11.56.46.png

But I wanted a timechart and a separate histogram for each combination of variable 2 and 3.

I also tried:



| timechart max(variable1) by variable2, variable3 



which doesn't work.

Could you kindly assist? the aggregation section in Trellis also doesn't seem to produce the wanted results. 


Labels (1)
0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!