Splunk Search

How can I build a chart that show the difference between two fields?

jfallon1
New Member

index=app sourcetype=application1 source=server1production with this search I get back two field Baseprice and finalprice. How can I build a chart that show the difference between finalprice and baseprice?

Tags (3)
0 Karma

Sukisen1981
Champion

not cleat what you want, I am guessing you want some sort of final price (y axis) over baseprice(xaxis) and also the difference.
If so, try this |chart values( finalprice) by baseprice| eval diff=finalprice-baseprice
Use format option in visualization > select diff as chart overlay
But as @adonio says, are your fields numerical?

0 Karma

adonio
Ultra Champion

are those numeric fields? meaning are the values for these fields are numbers?
if so, try this ... your search ... | eval diff = finalprice - baseprice | chart ...

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...