Splunk Search

Why am I unable to add field values over timechart?

P_Orourke
Loves-to-Learn Lots

Hi,

I have 2 timecharts where I need to show a TOTAL count across specified field values. The first timechart must show the total count over all field values and the 2nd timechart must show the total count over 2 field values. I am unable to incorporate a stats or eval function before the timechart function.

Here is what my timecharts currently look like:
Cannot add totals on timecharts.PNG

And here is the respective XML code:
Cannot add totals on timecharts - XML.PNG


Can you please help?

Many thanks,

Patrick

Labels (2)
0 Karma

maciep
Champion

I'm not sure if I understand exactly what you're asking, but maybe you can use addtotals after your timehart?

 

 

... | addtotals row=t col=f labelfield="Total"

 

 

That should calcualte the total sum of any number columns in each row and store in a field called "Total", which should be present on your chart then.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...