Splunk Search

Timechart and Table from same query

subtrakt
Contributor

HI!

What's the easiest way to create a time-chart and stats table with same query so I can create a dashboard, have a chart on the left, and stats table beside it without creating a seperate search?

Once I introduce the stats command, the time-chart comes back with no results.

Thanks!

Tags (3)
0 Karma

somesoni2
Revered Legend

You can utilize Splunk's PostProcess to create two outputs (table and chart) from virtually same query. In PostProcess search your can just format the output.

0 Karma

HiroshiSatoh
Champion

"_time" field is required to use "timechart" command. Are you ok?
It is easy to answer if there is a XML(or search statement).

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...