Splunk Search

chart

smanojkumar
Contributor

Hi,
I have total four fields lets say a,b,c and d. i want to show 'a' as a separate column and 'b','c' and 'd' as stacked and beside 'a' along with the sum of fields ('b'+'c'+'d') so that the count of these fields would come on the top of their column so that we can easily compare field 'a' with the count of rest.
Note:- I don't want separate column which would give sum of these three field. 

Click visualization select column chart
Click format and enable the stack mode.
select show data values as on
Click chart overlay and Click the text box and select Total field.
makeView as Axis as off
Click Apply.

After the above steps that i had mentioned, I can see the total on the top along with the line,

smanojkumar_0-1696587767375.png

 

I don't need line, Can you please help me in this.

Thanks in Advance!

Manoj Kumar S

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

It is not possible with standard column charts. You either have stacked column or separate columns, not a mixture.

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

It is not possible with standard column charts. You either have stacked column or separate columns, not a mixture.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...