Splunk Enterprise

Format to show data

Gabriel_CCI
Explorer

Hi.

Colleagues.
Somebody help me?

I have this query by current day (figure 1)

index=xxxx sourcetype=xxx earliest=-d@d latest=now |table control indicador cumplimiento| sort control
|chart values(cumplimiento) over control by indicador

the fields are: Empleo, Huérfanas, Uso, Control _time and Month

figure1.png

My problem is, I need also show data as showing in figure 2 (by month), but I don´t find the way to show as the figure (with month on top) 

figure 2.png

 

Somebody were a similar problem?

Labels (1)
Tags (1)
0 Karma

Gabriel_CCI
Explorer

 Hi, Isn´t possible with join of chart?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

No, the view you have is a table view and table views have unique column names, and do not have additional headers such as month as you have shown in your graphic.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

This is not possible with a single standard visualisation - you could have multiple panels with a different month in each panel.

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...