Hi
all the good day.
There are two questions
example:
package_by_nature_217
<panel>
<chart>
<title>Пользователи Портала</title>
<search>
<query>source="esb2.txt" host="prd-p-2frwz4wmp7tj" sourcetype="esb" "ClassId=217" | where (EventDetails LIKE "Отправлено%" AND NodeName="OMC_ZhKH") OR (EventDetails LIKE "%Получено%" AND NodeName="OMC_LK_CRM")| timechart span=5m count(eval(NodeName="OMC_ZhKH")) AS SendingCount, count(eval(NodeName="OMC_LK_CRM")) AS ReceivingCount by "tag::NodeName" | eval difference=SendingCount-ReceivingCount</query>
<earliest>0</earliest>
<latest></latest>
</search>
<option name="charting.axisLabelsY.majorUnit">1</option>
<option name="charting.chart">column</option>
<option name="charting.chart.showDataLabels">all</option>
<option name="charting.drilldown">none</option>
</chart>
</panel>
Description should be your legend and it can be placed at the bottom of the chart if you like:
charting.legend.placement
top | left | bottom | right | none
EG:
bottom
as for the timechart, I cant tell but you may have null or zero values in the beginning of your chart which is throwing it off center. There are several ways to handle this type of situation:
With the timechart command:
| timechart cont=false
| timechart usenull=false
Description should be your legend and it can be placed at the bottom of the chart if you like:
charting.legend.placement
top | left | bottom | right | none
EG:
bottom
as for the timechart, I cant tell but you may have null or zero values in the beginning of your chart which is throwing it off center. There are several ways to handle this type of situation:
With the timechart command:
| timechart cont=false
| timechart usenull=false
thank you so much!
My pleasure my man. Remember to pay it forward if and when you can!! Happy splunking!