Splunk Search

Creating a chart by search terms

beaumygod
New Member

If I have several terms I am searching for such as:

john OR frank OR mary OR jim OR jeff

How would I then create a chart of the sum or percentage of each search term, such as john returns 20 of 100 total results and is therefore 20% of the pie chart...

Tags (1)
0 Karma

ytamura
Path Finder

If you create a field that contains those names, you can just use the top command:

john OR frank OR mary OR jim OR jeff | top name

Field extractions can be predefined or done on the fly. Resource for field extraction: http://docs.splunk.com/Documentation/Splunk/latest/User/ExtractNewFields

Resource for top command:
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/top

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...