Dear all,
I have in splunk events of this simple structure fileldX=value, like
field1=..., field2=..., ... fieldN=...
Now I need to plot a stats of my data, something like
| chart avg(?), max(?) over field1, field2,.. fieldN
How should I express the '?'?
Do I need to create a syntetic field with values of my real filed names?
Thanks!
Did it with append:
search ... | chart avg(field1) as f1, avg(field2) as f2 ... | append [ search ... | chart max(field1) as f1, max(field2) as f2... ] | transpose | rename ...
Did it with append:
search ... | chart avg(field1) as f1, avg(field2) as f2 ... | append [ search ... | chart max(field1) as f1, max(field2) as f2... ] | transpose | rename ...
good Mr akazarov
i don't think like that.
Hi,
Try to enumerate with this: |eval new=mvappend(field1,mvappend(field2,mvappend(field3,field4)))... | makemv delim="," new
try like this:
...| chart avg(field*), max(field*) over field1, field2,.. fieldN
or
...| chart avg(*), max(*) over field1, field2,.. fieldN
over field1, field2
is not valid syntax, it says
Error in 'chart' command: Invalid argument: 'field2'