Splunk Search

What is the trick to stack column charts in splunk 6?

jaj
Path Finder

I have a basic query that generates the following results from splunk(6)'s' main query page (not a panel or anything):

success fail

100 4

What is the trick to get this displayed as a stacked 100% column chart? I have played with every configuration including stack mode: 100% stacked, multi series mode, split/combined, etc, et,c. All I get is on big column fill, nothing stacked. What am I missing here?

0 Karma
1 Solution

dart
Splunk Employee
Splunk Employee

This works for me :

| stats count as success | eval success = 100 | eval failure = 125 | eval dummy = 1 | table dummy success failure

View solution in original post

dart
Splunk Employee
Splunk Employee

This works for me :

| stats count as success | eval success = 100 | eval failure = 125 | eval dummy = 1 | table dummy success failure

jaj
Path Finder

great thanks! that works. stacked success/failure. I was missing the entire query structure. however, what is the reason behind the dummy eval? if I take the dummy out of the query it fails to stack. Is that a requirement to add another dummy node in there in order to get something to render?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...