Hi,
I'm new to Splunk and have written a simple search to see 4 trending values over a month.
auditSource XXX auditType XXX "detail.serviceName"="XXX" | timechart count by detail.adminMessageType
This gives me the values per day of 4 different admin message types e,g
Message 1 Message 2 Message 3 Message 4
01/01/19 5 10 4 7
02/01/19 15 20 7 15
03/01/19 8 3 6 16
When this converts to a line chart in visualizations, it shows me the value per day. I want it to report the total per message as the month goes on so you see the cumulative values. e.g
Message 1 Message 2 Message 3 Message 4
01/01/19 5 10 4 7
02/01/19 20 30 11 22
03/01/19 28 33 17 34
Can anyone help?
Cheers
... View more