Splunk Search

Is it possible to set a variable as the x-axis in a table?

kinda
Engager

Hello,

I don't specifically have anything down yet, I was just wondering if it would be possible to set a variable as the top row (x axis), the x axis would be auto populated by a variable.

Thanks in advance!

0 Karma
1 Solution

woodcock
Esteemed Legend

Yes, this is possible and very easy. You just use the chart (or timechart ) command instead of the stats command; see here:

https://answers.splunk.com/answers/32001/difference-between-stats-and-chart.html

View solution in original post

0 Karma

woodcock
Esteemed Legend

Yes, this is possible and very easy. You just use the chart (or timechart ) command instead of the stats command; see here:

https://answers.splunk.com/answers/32001/difference-between-stats-and-chart.html

0 Karma

kinda
Engager

Thats awesome! Thank you. I've never heard of/used the chart command. Thank you for your help!

0 Karma

woodcock
Esteemed Legend

See also xyseries (and it's opposite, untable ).

0 Karma

woodcock
Esteemed Legend

If in a dashboard, you create a control where the users selects from a list and this selection sets a token that the searches inside of the panels can reference. Is this what you mean?

0 Karma

kinda
Engager

A little,

I'm trying to get the x axis populated automatically with preset metadata that's available in my dashboard.

0 Karma

woodcock
Esteemed Legend

Start with this app:
https://splunkbase.splunk.com/app/1603/

I can help more if you can be much more specific.

0 Karma

kinda
Engager

I don't know if this is specific enough,

I have meta.hardware that has a list of devices. I would like to list those devices labeled in meta.hardware on the x axis without the need for hard coding those specific devices.

0 Karma

kinda
Engager

I don't know if this is important, but meta.hardware is listed as an 'interesting field', I don't know if I could somehow use that to my advantage

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...