Splunk Dev

Can anyone tell how to get below graph using splunk.

sxp5686
Explorer

I want two y-axis graph having percentage on left side and number (in thousands) on right side.And on x axis we should have total no. of cases on each day.

Tags (1)
0 Karma
1 Solution

cmerriman
Super Champion

Do you have th syntax worked out for number of cases, percentage and the other number?
If so, in the format option, there is a chart overlay button, click in that and choose the number field so that it displays on the right.
https://docs.splunk.com/Documentation/Splunk/7.0.1/SearchTutorial/Chartoverlays
If you don’t have the syntax worked out, if you could share some sample data, that could be helpful.

View solution in original post

naidusadanala
Communicator

There is an app splunk 6.x examples which provides basic concepts and also sample searches to populate dashboards fast and easily.

Hopefully it helps

https://splunkbase.splunk.com/app/1603/

cmerriman
Super Champion

Do you have th syntax worked out for number of cases, percentage and the other number?
If so, in the format option, there is a chart overlay button, click in that and choose the number field so that it displays on the right.
https://docs.splunk.com/Documentation/Splunk/7.0.1/SearchTutorial/Chartoverlays
If you don’t have the syntax worked out, if you could share some sample data, that could be helpful.

sxp5686
Explorer

Sorry but I do not have source code for this but take it like you are having two fields at the end of the search.
By using only that two fields you have to make the graph.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...