Splunk Search

How to edit my search to generate a report of Current Status over time?

wmusch
New Member

Greetings everyone.

I'm trying to do what I think is a simple task, but for some reason it is troubling. I loaded some CSV data into Splunk, and have this search:

Course="MYCOURSE*" Progres=100 | chart count by Course "Current Status"

Now, I get a result of my four courses, and the pass fail state (Current Status).
alt text

That is good, now I cant seem to generate this report over time. So basically I would like to see a bar graph, showing the pass/fail state for each course for each month. The trouble I think I'm running into is the use of chart and not timechart, however I seem to have trouble creating a timechart that breaks up the "Current Status" field that could be either pass or fail

Here is an example of the data set:
User User ID Course Course Start Date Course Completion Date Progress Current Average Current Status Time In Course
Jon ID1 Course 1 2/16/2017 16:25 2/17/2017 13:49 100 86 PASS 1h 17m
Doe ID1 Course 1 10/28/2016 3:43 11/7/2016 5:11 100 72 FAIL 107h 32m

0 Karma

woodcock
Esteemed Legend

Like this:

Course="MYCOURSE*" Progres=100 | eval CourseAndStatus = Course . ":" . $Current Status$ | timechart count BY CourseAndStatus 
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...