Splunk Search

How to change the scale of the distinct count of a field on a timechart?

RVDowning
Contributor

I have the following line:

timechart span=1d sum(TypeAErrors) , sum(TypeBErrors), dc(racf) as "Unique Ids"

but the dc(racf) is much larger than the other items displayed on the graph. I would ideally like dc(racf) / 10 so that it will scale more appropriately on the Y axis compared to the other two displayed items. But, I can't find any syntax that allows me to do this. Any ideas?

Tags (3)
1 Solution

wpreston
Motivator

You can also try this:

timechart span=1d sum(TypeAErrors) , sum(TypeBErrors), dc(eval(racf / 10)) as "Unique Ids"

View solution in original post

wpreston
Motivator

You can also try this:

timechart span=1d sum(TypeAErrors) , sum(TypeBErrors), dc(eval(racf / 10)) as "Unique Ids"

RVDowning
Contributor

That just gives me zeroes for dc(eval(racf / 10)). A "racf" is an alphanumeric ID. It is the count of these unique ids that I would like to divide by 10.

0 Karma

wpreston
Motivator

Yep, I realized that just a minute after I posted it, sorry about that (I blame a lack of caffine :-). The new search I posted should work exactly like you want.

0 Karma

RVDowning
Contributor

Yep, it works fine. Thanks much. I'm on my first cup of caffeine too. 😉

0 Karma

wpreston
Motivator

Oops, not qutie what I meant! Try this instead:

timechart span=1d sum(TypeAErrors) , sum(TypeBErrors), dc(racf) as TempVal | eval TempVal=TempVal/10 | rename TempVal as "Unique IDs"
0 Karma

MuS
Legend

Hi RVDowning,

in the UI visualization tab, click on Format and select Y-Axis. There you can set the Scale to Log instead Linear.
Maybe this fits your needs.

cheers, MuS

0 Karma

RVDowning
Contributor

Thanks for the suggestion, but the end user would totally freak. 🙂 But they could follow a simple division by 10, so when the mouseover showed 26.2 they would know it was 262.

0 Karma

MuS
Legend

HeHe, sounds like do not trust any statistics, you did not fake yourself

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...