Splunk® Enterprise

Dashboards and Visualizations

Acrobat logo Download manual as PDF

Splunk Enterprise version 7.2 will no longer be supported as of April 30, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
Acrobat logo Download topic as PDF

Data for charts

To build any chart, start with a transforming search that generates one or more data series.

A series is a sequence of related data points. These points can be plotted on a chart. For example, each line in a line chart shows one series.

7.1 line chart.png

When you run a transforming search, select the Statistics tab. Review the statistics table to see the series generated. After the first column, each additional column represents a series. A single series search generates two columns. A multiple series search generates three or more columns.

Different chart types are optimized to visualize one or more data series.

Chart name Optimized for single series? Optimized for multiple series? Notes
Pie Yes No Pie charts can only render a single series.
Bar Yes Yes
Column Yes Yes
Line Yes Yes Typically, line charts are used for multiple series.
Area No Yes Use an area chart to render multiple series.
Scatter No Yes Scatter charts work best with two data series.
Bubble No Yes Bubble charts work best with three data series.
Last modified on 18 June, 2020
PREVIOUS
Chart overview
  NEXT
Pie chart

This documentation applies to the following versions of Splunk® Enterprise: 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.1.0


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters