Splunk® Enterprise

Data Model and Pivot Tutorial

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Create a pivot chart

In the previous topic you used Pivot visualization editor to build a table. In this topic, you will use the same object to create chart visualizations.

Define a new Pivot

1. From the app navigation bar, select Pivot to enter the "Select a Data Model" page.

6.2tutorial pivot selectdatamodel.png

2. Choose the Buttercup Games data model and select the Successful Purchases child object.

6.2tutorial pivot selectobject.png

The New Pivot editor for Successful Purchases opens.

6.2tutorial pivot newtable.png

Visualization types are listed in the black sidebar that runs down the left-hand side of the Pivot editor. By default, the statistics table visualization is selected when you enter Pivot.

It can be helpful to begin building your pivot as a table and then switch over to the visualization of your choice. When you switch between pivot visualization types, Pivot will find the elements it needs to create the visualization, discard the elements it does not need, and notify you when needed elements need to be defined. This happens when you switch between tables and charts as well as between chart types.

Add Pivot elements

In the last topic, we looked at purchases by product ID and name. Now, let's report on the count of successful purchases by category.

Add a Split Row for the categoryId field.

1. Under Split Rows, click + and select categoryId from the list.

6.2tutorial pivot splitrow chart.png

2. Enter the label Category and click Add to table.

6.2tutorial pivot splitrow chart2.png

This returns the following Pivot table.

6.2tutorial pivot splitrow chart3.png

Change the visualization type

1. Click the Column Chart icon from the visualization bar.

6.2tutorial pivot columnviz.png

The New Pivot editor for the Column chart displays.

  • Column charts use the first split row element in pivot table definitions to provide their X-axis values. In this case, that Split Row is Category.
  • Column charts use the first column value element in pivot table definitions to provide their Y-axis values. Here, that Column Value is Count of Successful Purchases.

6.2tutorial pivot columnvizoptions.png

This data can also be visualized as a pie chart.

2. Click the Pie Chart icon from the visualization bar:

6.2tutorial pivot pieviz.png

The New Pivot editor for the Column chart displays.

  • Pie charts use the values from the first Split Row element (Category) to determine the number and colors of their slices.
  • Pie charts use the first Column Value element (Count of Successful Purchases) to determine the relative sizes of their slices.

6.2tutorial pivot pievizoptions.png

Mouseover a slice of the pie chart to view the metrics: Category, Count of Successful Purchases, and percentage of the total Count of Successful Purchases.

6.2tutorial pivot pievizslice.png

Next steps

In this chapter you created three pivots and saved two of them as reports. This last pivot chart, you will save as a dashboard panel. Continue to the next chapter to read about dashboards.

Create a pivot table
About dashboards

This documentation applies to the following versions of Splunk® Enterprise: 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters