Splunk Search

Why am I unable to add field values over timechart?

P_Orourke
Loves-to-Learn Lots

Hi,

I have 2 timecharts where I need to show a TOTAL count across specified field values. The first timechart must show the total count over all field values and the 2nd timechart must show the total count over 2 field values. I am unable to incorporate a stats or eval function before the timechart function.

Here is what my timecharts currently look like:
Cannot add totals on timecharts.PNG

And here is the respective XML code:
Cannot add totals on timecharts - XML.PNG


Can you please help?

Many thanks,

Patrick

Labels (2)
0 Karma

maciep
Champion

I'm not sure if I understand exactly what you're asking, but maybe you can use addtotals after your timehart?

 

 

... | addtotals row=t col=f labelfield="Total"

 

 

That should calcualte the total sum of any number columns in each row and store in a field called "Total", which should be present on your chart then.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...