Splunk Search

Line Chart single value over time

Blackninja5431
New Member

I have a log containing memory usage over a period of time. How can I plot a line graph where the x-axis is the time, and the y-axis is the amount of memory used at that time.

Tags (1)
0 Karma
1 Solution

Ayn
Legend

If you want to grab each data point, just using table with the fields _time and your field containing the memory info will do. Let's say the field is called memory_used:

... | table _time memory_used

After that, choose the chart view and apply the appropriate settings.

If you have loads of data points there is a risk of overwhelming the chart module with more points than it can handle. In that case, use timechart and some kind of statistical function for representing values in a certain time interval, like first, max or avg. You need to supply some kind of statistical function because timechart divides the events into discrete sets of time intervals, and it needs to know how to handle if there is more than 1 event in an interval.

... | timechart avg(memory_used)

View solution in original post

0 Karma

Ayn
Legend

If you want to grab each data point, just using table with the fields _time and your field containing the memory info will do. Let's say the field is called memory_used:

... | table _time memory_used

After that, choose the chart view and apply the appropriate settings.

If you have loads of data points there is a risk of overwhelming the chart module with more points than it can handle. In that case, use timechart and some kind of statistical function for representing values in a certain time interval, like first, max or avg. You need to supply some kind of statistical function because timechart divides the events into discrete sets of time intervals, and it needs to know how to handle if there is more than 1 event in an interval.

... | timechart avg(memory_used)
0 Karma

sam_jacob
Path Finder

After tabulating the data, what settings do you use for chart? I have the table needed to chart by two different fields, but how do I chart Field A by Field B?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...