Hello ! I have a field called Total Value that contains currency values .
I want to use these values in my chart , however Splunk is counting the events , and not the values themselves .
How do I change this ? For example : Value = Total Value
Hello
if your problem is to display values of the field Total values in your chart use a values() fonction after renaming Total values as Total_values
|chart values(Toatal_values)
Can you post some sample events and may be current non-working search? Also, expected output.