Splunk® Enterprise

Dashboards and Visualizations

Download manual as PDF

Download topic as PDF

Data for charts

To build any chart, start with a transforming search that generates one or more data series.

A series is a sequence of related data points. These points can be plotted on a chart. For example, each line in a line chart shows one series.

6.4 Line Chart example.png

When you run a transforming search, select the Statistics tab. Review the statistics table to see the series generated. After the first column, each additional column represents a series. A single series search generates two columns. A multiple series search generates three or more columns.

Different chart types are optimized to visualize one or more data series.

Chart name Optimized for single series? Optimized for multiple series? Notes
Pie Yes No Pie charts can only render a single series.
Bar Yes Yes
Column Yes Yes
Line Yes Yes Typically, line charts are used for multiple series.
Area No Yes Use an area chart to render multiple series.
Scatter No Yes Scatter charts work best with two data series.
Bubble No Yes Bubble charts work best with three data series.
Chart overview
Pie chart

This documentation applies to the following versions of Splunk® Enterprise: 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.6.0, 6.6.1, 6.6.2

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters