Splunk Graphs without TimeChart

Usually most graphs and chats use the timechart function, but for instances when you want the x axis to be individual events and not time, you need to use this:

 | chart values(value) by _time

Here _time is the internal splunk variable for every event. It keeps track of the time when this event was logged…

 

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s