Splunk Search

to get fields in bar chart

sahana
Engager

I have a search query statistical result values in the below format

Login mode

Total login

xxx

48

Yyyy

23

aaa

52

bbbb

73

 

Now I need to display a bar chart which shows the login in respective of the login mode and the time selection in the query

 

for example:

sahana_0-1707368814863.png

 

Labels (1)
0 Karma

sahana
Engager

It is supposed to be a bar chart y axis denotes the login count and x- axis represents the time period selection we do in our search.... Those bars are representation of total count values of xxx,yyyy,aaa,bbb

0 Karma

yuanliu
SplunkTrust
SplunkTrust

What do you mean by "total count"?  There is only one total in my vocabulary.  That's the opposite of the mockup chart in your original post that shows multiple bars at each depicted time point.  If you don't need to break down, all you need is

| timechart count

 

0 Karma

yuanliu
SplunkTrust
SplunkTrust

You mean something like this?

| timechart count by "Login mode"
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...