I've found this on the Splunk wiki that gives great examples on how to graph several sources and their cumulative totals: http://wiki.splunk.com/Community:Search_Report:_How_To_Create_a_Chart_of_Hourly_and_Accumulated_Inde...
Is it possible to use a similar method, but to only graph the cumulative total and not each of the individual sources that make up that total?
Just add a table/fields command to remove other columns.
Query version from Blogpost
index=_internal group="per_index_thruput" earliest=@d latest=@h
| eval mb=kb/1024
| timechart span=1h sum(mb) as HourlyTotal by series
| addtotals fieldname=HourlyTotal
| streamstats sum(HourlyTotal) AS AccumulatedTOTAL
| table _time AccumulatedTOTAL
Another version
index=_internal group="per_index_thruput" earliest=@d latest=@h
| eval mb=kb/1024
| timechart span=1h sum(mb) as HourlyTotal
| streamstats sum(HourlyTotal) AS AccumulatedTOTAL
| table _time AccumulatedTOTAL
Just add a table/fields command to remove other columns.
Query version from Blogpost
index=_internal group="per_index_thruput" earliest=@d latest=@h
| eval mb=kb/1024
| timechart span=1h sum(mb) as HourlyTotal by series
| addtotals fieldname=HourlyTotal
| streamstats sum(HourlyTotal) AS AccumulatedTOTAL
| table _time AccumulatedTOTAL
Another version
index=_internal group="per_index_thruput" earliest=@d latest=@h
| eval mb=kb/1024
| timechart span=1h sum(mb) as HourlyTotal
| streamstats sum(HourlyTotal) AS AccumulatedTOTAL
| table _time AccumulatedTOTAL
Thank you, this is almost perfect. Is there a way to format the time bucket on the chart? As it is now, the format makes for a very ugly chart if graphing more than a handful of columns.
I've figured it out. This search works perfect for my needs:
index=_internal group="per_index_thruput" earliest=@d latest=@h
| eval mb=kb/1024
| timechart span=1h sum(mb) as HourlyTotal by series
| addtotals fieldname=HourlyTotal
| streamstats sum(HourlyTotal) AS AccumulatedTOTAL
| table _time AccumulatedTOTAL
| eval _time=strftime(_time, "%m/%d %H:%M")