Splunk Search

X-axis of chart skips over values.

CCoomber
Engager

Hi, after a search I have a table like this:

row VAL count
1   0   169 
2   1   3 
3   4   4 
4   9   1 
5   10  12 

I want to plot it as a column graph. However, on the x-axis I find that my VALs miss out values such as 2,3,5,6,7,8, etc. as in the table.

Ideally I want my table to look like:

row VAL count
1   0   169 
2   1   3 
3   2   0 
4   3   0 
5   4   4 
6   5   0 
7   6   0 
8   7   0 
9   8   0 
10  9   1 
11  10  12 

The there a way of telling splunk I want a row in the table for each integer between 0 and 11, and to fill empty ones with 0?

I've found bucketing by VAL works to an extent, as it makes buckets regularly even if they have nothing in, but I'd rather not have my x-axis reading 1-2,2-3,3-4 etc.

Thanks!

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Add this to your search pipeline:

... | makecontinuous VAL | fillnull count

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Add this to your search pipeline:

... | makecontinuous VAL | fillnull count

martin_mueller
SplunkTrust
SplunkTrust

That's possible, considering that makecontinuous is adding new values to VAL that did not come from the original search, so drilling down on that may confuse Splunk's default behaviour.

One way that should always work would be to build your own drilldown using Advanced XML.

0 Karma

CCoomber
Engager

This is almost exactly perfect, however if this search is making a column graph on a view (in simple XML) clicking on a column will no longer drilldown and give me events with VAL equal to this column's value. It seems both makecontinuous and fillnull kill the ability to drilldown.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...