Splunk Search

Plot time series chart based on values selected where in value can single or multiple

R_Ramanan
Loves-to-Learn

I am using query as below 

index="test" sourcetype="reports"
| bin _time span=1m | stats values(a) as a values(b) as b values(c) as c values(d) as d values(e) as e values(f) as f values(g) as g by par1, _time
| append [search (index="test" sourcetype=reports_metadata) | table par1,par2,par3,par4,par5,par6,par7,par8,par9,par10,par11,par12]
| eventstats values(par2) as par2,values(par3) as par3, values(par4) as par4, values(par5) as par5, values(par6) as par6, values(par7) as par7, values(par8) as par8,values(par9) as par9,values(par10) as par10,values(par11) as par11,values(par12) as par12, values(a) as a alues(b) as b values(c) as c values(d) as d values(e) as e values(f) as f values(g) as g by par1
| search par2 IN ("*") par3 IN ("*") par3 IN ("*") par4 ("*") par5 IN ("*") par6 IN ("*") par7 IN ("*") par8 IN ("*") par9 IN ("*") par10 IN ("*")
| search par1="*"ar2 IN ("*") par3 IN ("*") par3 IN ("*") par4 ("*") par5 IN ("*") par6 IN ("*") par7 IN ("*") par8 IN ("*") par9 IN ("*") par10 IN ("*") par11 IN ("*") par12 IN ("*")
| timechart span=15m values(a) by par1 limit=0

In this query, I am able to use any values rangin from a to g and plot a time series graph.

I need help in plotting time series for one or more values and also how this value can be used to pick from a drop down filter 

#timeseries #timechart #xyseries #multiseries #multivalue 

Labels (1)
0 Karma

R_Ramanan
Loves-to-Learn

Report data would be as below

par1timebefglmnrs
SNC112/5/2024 16:30299367-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9312.91
SNC112/5/2024 16:45299364-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9512.87
SNC112/5/2024 17:00299369-7.7-7.9-7.71.00E-371.00E-371.90E-0713.8912.88
SNC112/5/2024 17:15299364-7.6-7.9-7.71.00E-371.00E-371.80E-0713.9212.89
SNC112/5/2024 17:30299368-7.6-7.9-7.71.00E-371.00E-371.90E-0713.8712.83
SNC112/5/2024 17:45299362-7.6-7.9-7.71.00E-371.00E-371.90E-0713.9212.78
SNC112/5/2024 18:00299368-7.6-7.9-7.71.00E-371.00E-371.80E-0713.9212.88
SNC112/5/2024 18:15299371-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9512.88
SNC112/5/2024 18:30299359-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9412.83
SNC112/5/2024 18:45299362-7.7-7.9-7.71.00E-371.00E-371.80E-0713.9212.86
SNC112/5/2024 19:00299369-7.7-7.9-7.71.00E-371.00E-371.90E-0713.8912.85
SNC112/5/2024 19:15299365-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9212.89
SNC112/5/2024 19:30299368-7.6-7.9-7.71.00E-371.00E-371.80E-0713.912.75
SNC112/5/2024 19:45299369-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9212.85
SNC112/5/2024 20:00299363-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9312.89
SNC112/5/2024 20:15299358-7.7-7.9-7.71.00E-371.00E-371.90E-0713.9312.85
SNC212/5/2024 16:30259482-7.6-6.9-7.69.00E-351.00E-340.00119.589.54
SNC212/5/2024 16:45259479-7.5-6.9-7.68.00E-351.00E-340.00119.599.53
SNC212/5/2024 17:00259478-7.5-6.9-7.68.00E-351.00E-340.00119.599.56
SNC212/5/2024 17:15259484-7.5-6.9-7.65.00E-351.00E-340.00119.619.55
SNC212/5/2024 17:30259487-7.6-6.9-7.66.00E-352.00E-340.00119.569.52
SNC212/5/2024 17:45259480-7.5-6.9-7.68.00E-351.00E-340.00119.579.53
0 Karma

R_Ramanan
Loves-to-Learn

Attached sample data of two tables.  for each SNC1, SNC2, there will be data for each 15 mins and values can be different. Now the idea is to do timeseries for each SNC any of the values and filtering will be mainly based on SNC and any of the values (one or more values at the same time )

0 Karma

R_Ramanan
Loves-to-Learn

reports_metadata file contains data as below

snc_labeldeployment_statepar1par2par3par4par5par6par7par8par9par10par11par12par13par14par15par16par17par18par19
SNC1discoveredL0CPC410037.5ABCMOTRABC-0101XYZ-01011-1-115-7-115.5 -23.697888133.879791  ABAA
SNC2discoveredNL0CPC420037.5DCEOTRDCE-0102CSNO-01017-8-110-2-215.515.5-30.296649153.113164-28.864117153.047084BBAB
SNC3discoveredL0CPC7430037.5XYZMOTRABC-0101PTMA-010115-7-115-7-115.515.5-30.296649153.113164-31.431357152.914377AAAD
SNC4discoveredNL0CPC6410037.5ABCMOTRDCE-0102BRDE-010215-7-110-2-215.515.5-27.357494153.022632-27.471961153.025407CCCA
SNC5discoveredL0CPC4420037.5ABBMOTRCZWX-0201HABC-010110-2-21-1-115.515.5-33.797823151.180644-33.896447151.193881DEDZ
0 Karma

tscroggins
Influencer

Hi @R_Ramanan,

Can you provide a small set of sample data? If a, b, c, ..., g are only related to par2, par3, par4, ..., par12 by par1, then par1 is likely your only filterable parameter.

0 Karma

R_Ramanan
Loves-to-Learn

@tscroggins, hope the information is helpful, please let me know if you need any additional details

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...