Splunk Enterprise

help on a pie chart

jip31
Builder

hi

i try to do a pie chart from the code below but it doesnt works

what is wrong please?

 

index_mesu sourcetype=sig sig_app="$site$" 
| fields sig_id site sig_app 
| rename sig_app as application 
| stats dc(sig_id) as Total by site application
| sort - Total limit=10
Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
Legend

A pie chart normally only has 2 dimensions (name and value), you have 3 (Total site application).

View solution in original post

0 Karma

ITWhisperer
Legend

A pie chart normally only has 2 dimensions (name and value), you have 3 (Total site application).

View solution in original post

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!