Splunk® Enterprise

Dashboards and Visualizations

Download manual as PDF

Download topic as PDF

Pie chart

Use a pie chart to show how different field values combine over an entire data set. Each slice of a pie chart represents the relative importance or volume of a particular category.

Data formatting

Pie charts represent a single data series.

Use a transforming command in a search to generate the single series.

For example, count events in each source field category.

 ...| stats count by source 

Check the Statistics table after running the search to make sure that a single series generated. The table should have two columns.

The example search generates the following table.

Pie chart stats table.png

The first table column contains labels for each pie slice. The second column contains the numerical values that correspond to each label. The numerical values determine the relative size of each slice.

If the search generates a table with more than two columns, the extra columns are ignored.

Configuration options

You can use the Format menu to configure the following pie chart components.


Drilldown in a pie chart lets users click on a pie slice to open a secondary search using the clicked values. You can enable or disable drilldown in the Dashboard editor. See Use drilldown for dashboard interactivity for more details.

Minimum size

Set a minimum percentage size to apply when there are more than 10 slices. Data values below the minimum percentage are combined into an other slice.

Create a pie chart

Review the following details about building pie charts.


  1. Write a search that uses a transforming command to aggregate values in a field.
  2. Run the search.
  3. Select the Statistics tab below the search bar. The statistics table here should have two columns.
  4. Select the Visualization tab and use the Visualization Picker to select the pie chart visualization.
  5. (Optional) Use the Format menu to configure the visualization.


This search portion aggregates events by Code field values.

... | stats count by Code

The search generates a single data series representing values in the Code field.

6.4 pie chart example.png

The chart is configured with a 5% minimum size. Field values that represent less than 5% of the total data set are combined into an other slice.

This search uses the bytes and source fields to generate a single series.

index = _internal | chart avg(bytes) over source

Here, the source column provides pie slice labels. The avg(bytes) column provides the relative size of each slice, as percentages of the sum of avg(bytes) returned by the search.

Data for charts
Column and bar charts

This documentation applies to the following versions of Splunk® Enterprise: 6.6.0, 6.6.1, 6.6.2

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters