Dashboards & Visualizations

Chart Overlay: How to sum and avg of a single field and apply it in chart overlay?

gokikrishnan198
New Member

index=source sourcetype=type|timechart sum(TotalTime) avg(TotalTime)
Getting a chart below
alt text

Unable to use the clause "over" in timechart command like "timechart sum(TotalTime) over avg(TotalTime) by EM"
Unable to calculate sum if I use stats command. Need assistance Please.

0 Karma

adonio
Ultra Champion

hello there,

maybe use the chart overlay function within your visualization options.
run this search anywhere and follow the screenshot below:

| gentimes start="07/16/2018:00:00:00" end="07/20/2018:10:00:00" increment=15m
| eval total_time= random()%1000
| eval _time = starttime
| timechart span=2h  sum(total_time) as sum_total_time avg(total_time) as avg_total_time

alt text

hope it helps

0 Karma

gokikrishnan198
New Member

Hi @Adonio,

Apologies. I am unable to follow the code that was provided.

Let me explain the thing here again.
If there is a Service A . It takes time to run. Need to calculate average and total time elapsed for the service. Thanks,

0 Karma

adonio
Ultra Champion

@gokikirishan, the code is just an example for your use case
the screenshot shows you how to do chart overlay

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...