Splunk Search

How to overlay a single static line against a timechart with multiple series without displaying each series as its own line?

burras
Communicator

I have what should be a fairly simple timechart that I'm looking to do.

In our data, we have a field (util) that represents percent utilization at each of 3 sites. The sites are configured for (n+1) capacity so we want to have a manually entered capacity line at 66% (to show where if we had a site failure we'd still be able to maintain service on the 2 other sites). The general way I'd chart this without any sort of capacity line is |timechart max(util) by site. To add in the capacity line we'd generally do |eval capacity=66 |timechart max(util),capacity by site. However, when we do this, we end up with 3 separate capacity notations on the time chart: capacity:site1, capacity:site2, capacity:site3. And while we can pick all 3 as overlays so they show a single line, they still show as 3 separate notations in the legend.

What's the best way to overlay a single static line against a timechart with multiple series without showing as a per series result?

1 Solution

gokadroid
Motivator

If the capacity=66 and max(util) are of same unit and can be plotted in same graph then can you try to add your eval command after timechart:

|timechart max(util) by site | eval capactity=66

That should keep one line of 66 on the timechart with all others the way you want.

View solution in original post

gokadroid
Motivator

If the capacity=66 and max(util) are of same unit and can be plotted in same graph then can you try to add your eval command after timechart:

|timechart max(util) by site | eval capactity=66

That should keep one line of 66 on the timechart with all others the way you want.

burras
Communicator

Worked perfectly - thanks!

gcusello
SplunkTrust
SplunkTrust

Hi burras,
I'm out so I cannot use my pc.
Every way, you can see the License usage Report to configure your overlay.
If you need Tomorrow morning I'll be again at work.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...