Splunk Search

chart

smanojkumar
Contributor

Hi,
I have total four fields lets say a,b,c and d. i want to show 'a' as a separate column and 'b','c' and 'd' as stacked and beside 'a' along with the sum of fields ('b'+'c'+'d') so that the count of these fields would come on the top of their column so that we can easily compare field 'a' with the count of rest.
Note:- I don't want separate column which would give sum of these three field. 

Click visualization select column chart
Click format and enable the stack mode.
select show data values as on
Click chart overlay and Click the text box and select Total field.
makeView as Axis as off
Click Apply.

After the above steps that i had mentioned, I can see the total on the top along with the line,

smanojkumar_0-1696587767375.png

 

I don't need line, Can you please help me in this.

Thanks in Advance!

Manoj Kumar S

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

It is not possible with standard column charts. You either have stacked column or separate columns, not a mixture.

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

It is not possible with standard column charts. You either have stacked column or separate columns, not a mixture.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...