Splunk Search

Scatter plot whose x axis defaults to an incrementing index/count

chashi
New Member

In Excel, it's possible to create a scatter plot and only feed in one column of data and the X axis will default as a count/frequency, incrementing from 0 to the number of values/rows being plotted. Is the same thing possible in Splunk? I'd like to feed in one field for the Y axis and have the X axis default to 0, 1, 2, 3, etc.

0 Karma
1 Solution

niketn
Legend

@chashi instead of performing x-axis aggregation using stats, you can use streamstats to create a counter | streamstats count as sno. Try the following run anywhere example using Splunk's internal index.

index="_internal" sourcetype=splunkd log_level!=INFO NOT (component IN ("Metrics","PeriodicHealthReporter"))
| eval event_message=substr(event_message,1,30)
| stats count by component event_message
| streamstats count as sno
| stats last(sno) as "X-Axis" max(count) as "Y-Axis" by component event_message

If you want to show all data labels on x-axis with interval of 1, you can add the following Simple XML configuration to you chart for x-axis label major unit.

<option name="charting.axisLabelsX.majorUnit">1</option>
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

niketn
Legend

@chashi instead of performing x-axis aggregation using stats, you can use streamstats to create a counter | streamstats count as sno. Try the following run anywhere example using Splunk's internal index.

index="_internal" sourcetype=splunkd log_level!=INFO NOT (component IN ("Metrics","PeriodicHealthReporter"))
| eval event_message=substr(event_message,1,30)
| stats count by component event_message
| streamstats count as sno
| stats last(sno) as "X-Axis" max(count) as "Y-Axis" by component event_message

If you want to show all data labels on x-axis with interval of 1, you can add the following Simple XML configuration to you chart for x-axis label major unit.

<option name="charting.axisLabelsX.majorUnit">1</option>
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...