Dashboards & Visualizations

How to make a timechart for a search?

acceo_purchasin
Explorer

Hi,
I have the following search and need to make a timechart of NoicerValues by APname. I tried this but there are not results.

index="ti-wifi" sourcetype=csv_wifi name=bsnMobileStationMacAddress
| rename values as MobileStationMacAddress
| join ip
   [search index="ti-wifi" name=bsnMobileStationRSSI
   | rename values as MobileStationRSSI ]
| join ip
   [search index="ti-wifi" name=bsnMobileStationSnr
   | rename values as MobileStationSnr]
| join ip
   [search index="ti-wifi" name=bsnMobileStationAPMacAddr
   | rename values as MacAddress ]
| lookup wifi.csv MacAddress OUTPUT APname
| eval MacAddress =APname
| eval totalCount = (MobileStationRSSI - MobileStationSnr)
| stats sum(totalCount) as totalNoice, count as Sessions by APname
| eval  NoiceFloor = round(totalNoice/Sessions,0)
| timechart list(NoiceFloor) by APname

Thank you

Ed

Tags (1)
0 Karma

pradeepkumarg
Influencer

list is not an appropriate function to use over timechart. Try avg or other mathematical aggregation functions

| timechart avg(NoiceFloor) by APname
0 Karma

acceo_purchasin
Explorer

Thank you for your answer, I already tried it but I received : Non result found.

Best regards

0 Karma

xpac
SplunkTrust
SplunkTrust

Can you show the results you get when you remove the last part of your search (the | timechart ...)?

0 Karma

acceo_purchasin
Explorer

I receive the following table :

APname totalNoice Sessions NoiceFloor
wap-3 -72 1 -72
wap-7 -755 8 -94

wap-8 -1081 11 -98
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

Best regards

0 Karma

xpac
SplunkTrust
SplunkTrust

At this point, your stats() has already removed all time information, so it's no longer possible to draw a timechart.
Do you actually want a time chart, that means the values for one or multiple series over a certain time frame? If yes, what time frame would that be?

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...