Hi,
I have the following data that I want to represent on a graph, but It's not coming out properly:
Data is in the following format:
Column Name: 03_DEC_2017 04_DEC_2017
Data 1 6
2 3
That Data I want on my X axis by date. So I want 3rd Dec and 4th Dec
On my Y axis I have the data:
DEPT
1
2
3
4
5
Each date has department value associated to it.
Can someone please help me.
This is my current query:
index=xxxsourcetype=csv source=xxx | table 03_DEC_2017, 04_dec_2017, DEPT, ITEM
I'm using the graph function in splunk/
Try this
index=xxxsourcetype=csv source=xxx | timechart count by DEPT span=1d