Splunk Search

Using calculated values to create timechart -- too many columns

Builder

Hello, I know this type of question has been asked several times: ex:

http://answers.splunk.com/answers/11020/display-calculated-values-in-a-timechart

But I have tried that example and am getting column bars for my total when I just want column bars for my calculated values. Im basically trying to create a chart that return the percentages of a total value but I dont want the values I used (count, total) to be included on the timechart. Here is my query:

XXXXXX NOT(resultType=XXXX) activity=foo OR activity=bar
| timechart span=1h count by activity
| eval total = foo + bar
| eval percAddTrials = round(foo100/total,1)
| eval percAddSub = round(bar
100/total,1)

I've been working on this for a few days. I started initially trying to use appendcols and that seemed to work somewhat as well:

XXXXX NOT(resultType=XXX) activity=foo
| timechart span=1h count as foototal
| appendcols
[search XXXXX NOT(resultType=XXX) activity=bar
| timechart span=1h count as bar
total]
| eval total = foototal + bartotal
| eval percFoo = round(foototal*100/total,1)
| eval percBar = round(bar
total*100/total,1)

But this gave me the same issue of displaying the column bars of total and the counts. Any suggestions?

0 Karma
1 Solution

Path Finder

If you only want the percAddTrials and percAddSub to remain just do the following with your search (add fields fommand):

XXXXXX NOT(resultType=XXXX) activity=foo OR activity=bar | timechart span=1h count by activity | eval total = foo + bar | eval percAddTrials = round(foo100/total,1) | eval percAddSub = round(bar100/total,1) | fields percAddTrials, percAddSub

View solution in original post

Path Finder

If you only want the percAddTrials and percAddSub to remain just do the following with your search (add fields fommand):

XXXXXX NOT(resultType=XXXX) activity=foo OR activity=bar | timechart span=1h count by activity | eval total = foo + bar | eval percAddTrials = round(foo100/total,1) | eval percAddSub = round(bar100/total,1) | fields percAddTrials, percAddSub

View solution in original post

Builder

That worked Its always the simple stuff. Thanks!

0 Karma