Splunk Search

Why am I unable to add field values over timechart?

P_Orourke
Loves-to-Learn Lots

Hi,

I have 2 timecharts where I need to show a TOTAL count across specified field values. The first timechart must show the total count over all field values and the 2nd timechart must show the total count over 2 field values. I am unable to incorporate a stats or eval function before the timechart function.

Here is what my timecharts currently look like:
Cannot add totals on timecharts.PNG

And here is the respective XML code:
Cannot add totals on timecharts - XML.PNG


Can you please help?

Many thanks,

Patrick

Labels (2)
0 Karma

maciep
Champion

I'm not sure if I understand exactly what you're asking, but maybe you can use addtotals after your timehart?

 

 

... | addtotals row=t col=f labelfield="Total"

 

 

That should calcualte the total sum of any number columns in each row and store in a field called "Total", which should be present on your chart then.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...