All Apps and Add-ons

Visualization question: Column vs Line chart

jonydupre
Path Finder

Hi,

I currently have a search which counts each unhealthy system for a set number of days. The idea is to get an idea if the numbers are increasing or decreasing. Currently I have a Column chart visualization, but I rather have a Line chart which give more of a visual perspective of the situation. This is the search:

index=linux  earliest=-1d@d latest=@d "healthcheck: System not healthy" | dedup host | stats count by host
| stats count as TotalA
| appendcols 
[search index=linux earliest=@d latest=now "healthcheck: System not healthy" | dedup host | stats count by host 
| stats count as TotalB]
| appendcols 
[search index=linux earliest=-2d@d latest=-1d@d "healthcheck: System not healthy" | dedup host | stats count by host 
| stats count as TotalC]
| appendcols 
[search index=linux earliest=-3d@d latest=-2d@d "healthcheck: System not healthy" | dedup host | stats count by host
| stats count as TotalD]
| appendcols 
[search index=linux earliest=-4d@d latest=-3d@d "healthcheck: System not healthy" | dedup host | stats count by host 
| stats count as TotalE]       
| eval Yesterday=TotalA 
| eval Today=TotalB
| eval Daybeforeyesterday=TotalC
| eval Daybeforethat=TotalD
| eval Daybeforethat1=TotalE
| fields HealthchecksError, Daybeforethat1, Daybeforethat, Daybeforeyesterday, Yesterday, Today

alt text

That's an example of the current visualization. Any idea which one I should choose or what I should change in the search? I can't get one to work..

Thanks a lot!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...