Splunk Search

chart

smanojkumar
Contributor

Hi,
I have total four fields lets say a,b,c and d. i want to show 'a' as a separate column and 'b','c' and 'd' as stacked and beside 'a' along with the sum of fields ('b'+'c'+'d') so that the count of these fields would come on the top of their column so that we can easily compare field 'a' with the count of rest.
Note:- I don't want separate column which would give sum of these three field. 

Click visualization select column chart
Click format and enable the stack mode.
select show data values as on
Click chart overlay and Click the text box and select Total field.
makeView as Axis as off
Click Apply.

After the above steps that i had mentioned, I can see the total on the top along with the line,

smanojkumar_0-1696587767375.png

 

I don't need line, Can you please help me in this.

Thanks in Advance!

Manoj Kumar S

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

It is not possible with standard column charts. You either have stacked column or separate columns, not a mixture.

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

It is not possible with standard column charts. You either have stacked column or separate columns, not a mixture.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...