Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Need another column in chart

$
0
0
Forgive my newbiness. I've been working with Splunk for many years but not developing reports. I have a report that works well. After the search criteria and all are completed, the following shows the report... timechart span=30m max(ms) as MS, by server | eval Time=strftime(_time,"%H:%M:%S %m/%d/%Y") | untable Time, server, ms | sort +Time I got Time and server and ms columns beautifully. However, there is a field called APP that I would like to also display a column for. How can I get the report to included this column?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>