Dashboards & Visualizations

Stacked column with line overlay in Splunk 6.1 dashboard

mcomfurf
Path Finder

I'm trying to create a chart overlay that mixes a stacked column (breakdown of event counts) with a line overlay (average time for all events) in a Splunk 6.1 dashboard panel. I'm able to make the stacked column OR the line in a dashboard panel; I'm able to overlay the line over a non-stacked column with the total count, and I'm able to run my search in Search and then set the visualization to an overlay for a report, but once the latter is imported to a dashboard I lose the overlay.

Here's the XML for the attempted panel:




Overlay 3
(sourcetype="blahblahblah" | eval duration=duration+(_time-(strptime(lastmodifiedtime,"%Y-%m-%d %H:%M:%S"))) | where duration < 86400 | timechart span=1d avg(duration) | fillnull value=0 | appendcols [ search index=main sourcetype="blahblahblah" | eval duration=duration+(_time-(strptime(lastmodifiedtime,"%Y-%m-%d %H:%M:%S"))) | where duration < 86400 | eval duration_min=duration/60 |rangemap field=duration_min red=60-9999999 yellow=15-60 green=0-15 |rangemap field=duration_min red=60-9999999 yellow=15-60 green=0-15 | timechart span=1d count by range ]
-7d@h
now
ellipsisNone
0
visible
visible
visible
linear
linear
false
inherit
column
gaps
0.01
stacked
Average
shiny
{"red": 0xFF0000, "yellow": 0xFF9900, "green":0x009900, "Average":0x639BF1, "NULL":0xC4C4C0}
all
0
ellipsisMiddle
right


0 Karma

harshal_chakran
Builder

This one works for me:

<row>
<panel>
<chart>
<title>Chart Overlay w/ Dual Axis</title>
<searchString>index=_internal | timechart count by sourcetype</searchString>
<option name="charting.axisTitleX.visibility">collapsed</option>
<option name="charting.axisTitleY.visibility">collapsed</option>
<option name="charting.axisTitleY2.visibility">visible</option>
<option name="charting.axisX.scale">linear</option>
<option name="charting.axisY.scale">linear</option>
<option name="charting.axisY2.enabled">true</option>
<option name="charting.axisY2.scale">inherit</option>
<option name="charting.chart">column</option>
<option name="charting.legend.placement">bottom</option>
<option name="charting.legend.masterLegend">null</option>
<option name="height">250px</option>
<option name="charting.chart.overlayFields">splunkd</option>
<option name="charting.axisY2.enabled">true</option>
<option name="charting.axisY2.scale">inherit</option>
<option name="charting.axisY2.fields">splunkd</option>
<option name="charting.fieldColors">{"total": 0x639BF1, "splunkd":0xFF5A09}</option>
<option name="charting.axisLabelsX.majorLabelStyle.overflowMode">ellipsisNone</option>
<option name="charting.axisLabelsX.majorLabelStyle.rotation">0</option>
<option name="charting.chart.nullValueMode">gaps</option>
<option name="charting.chart.sliceCollapsingThreshold">0.01</option>
<option name="charting.chart.stackMode">stacked</option>
<option name="charting.chart.style">shiny</option>
<option name="charting.drilldown">all</option>
<option name="charting.layout.splitSeries">0</option>
<option name="charting.legend.labelStyle.overflowMode">ellipsisMiddle</option>
</chart>
</panel>
</row>

mcomfurf
Path Finder

That's still putting the Average, which I've designated as the overlay series, as part of the stacked column instead of overlaying it.

0 Karma

rodrigo_santos
Explorer

options:

<option name="charting.chart.overlayFields">You_VARIABLE</option> 
<option name="charting.axisY2.enabled">true</option> 
<option name="charting.axisY2.scale">inherit</option> 
<option name="charting.axisY2.fields">You_VARIABLE</option> 
<option name="charting.fieldColors">{"total": 0x639BF1, "You_VARIABLE":0xFF5A09}</option> 
0 Karma

harshal_chakran
Builder

See the Chart Overlay example in Splunk 6.X Dashboards Examples

0 Karma

harshal_chakran
Builder

Try replacing the searchstrings here with yours, and on "edit panel" change the general chart to Stacked one.
I hope this one helps

0 Karma

mcomfurf
Path Finder

The example is a column + line, not a stacked column + line overlay. As I said, "I'm able to overlay the line over a non-stacked column with the total count."

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...