Splunk Search

how to make column chart with filter by host and upper bound

mishaaaaaaaaaa
Explorer

Hi, splunk comunity!
How can i make query which print some info in column chart filtred by hosts and also upper bound line?
I try to do something like this:
....
| eval top=some logic to calculate top value
| timechart sum(someInfo) as "counter" max(top) as "upper bound" by host
....
but i have columns which contains value of upper bound for each host, but not an upper bound line

Tags (1)
0 Karma

whrg
Motivator

I believe you are looking for a chart overlay. Check out this page: Chart overlay example (dual axis).

So edit your column chart by clicking on "Format", then on "Chart Overlay" and then select the "upper bound" field.

0 Karma

vishaltaneja070
Motivator

@mishaaaaaaaaaa
Can you please explain the requirement again with any snippet if you have?

0 Karma
Get Updates on the Splunk Community!

Bridging the Gap: Splunk Helps Students Move from Classroom to Career

The Splunk Community is a powerful network of users, educators, and organizations working together to tackle ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...