Dashboards & Visualizations

splunk visualization

chookp
Explorer

hi i had made a stats table base on below command
alt text

and under my visualization is :
alt text

i would like to ask if there is a way to have additional information at the X-axis example the current X axis have the DESCRIPTION and count(VALUE), but i would like to have the VALUE (RUN and STOP) information inside too

Tags (1)
0 Karma

chookp
Explorer

alt text

i am sorry but i have no idea how i can fix my query into the query that you have given, i am thinking of if i am able to click on the bar and it will show my VALUE base on the DESCRIPTION on top, but different ASSET_NAME have different number of DESCRIPTION and the VALUE are also different . base on the query you given you have fix the result to show as 4 and the count value as 24 i suppose?

0 Karma

to4kawa
Ultra Champion

Have you try my query and see the result?

I created the query from your result.

I don't know what you do not understand it.

Please see the reference and try line by line.

https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Makeresults

0 Karma

to4kawa
Ultra Champion
| makeresults count=4
| streamstats count 
| fillnull DESCRIPTION VALUE ASSET_NAME 
| eval DESCRIPTION="STN DR SUMP Pump ".ceil(count/2)." Run/Stop Status Ante RM 1"
| eval VALUE=mvindex(split("RUN/STOP","/"),(count % 2)-1)
| eval ASSET_NAME="XPO/CIV/DES/DSS11"
| eval "count(VALUE)" = 24 - ceil(count/2)
| table DESCRIPTION VALUE ASSET_NAME count(VALUE)
| rename COMMENT as "this is sample you provide. from here, the logic"

| eval ASSET_NAME=ASSET_NAME.":".VALUE 
| xyseries DESCRIPTION ASSET_NAME count(VALUE)

try Visualization >> Column Chart stacked

0 Karma

chookp
Explorer

hi thanks for the help i am able to get the visualization, but this is on a fix ASSET_NAME if i have my ASSET_NAME with a lot of variables is there a way to use REX to do it?

0 Karma

to4kawa
Ultra Champion

"this is sample you provide. from here, the logic"
try logic to your query.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...