How it works...

This recipe further familiarized you with the Pivot interface. Directly selecting to pivot off the Web Access > All Web Access > Error data model dataset filtered the data to just web access data containing errors, due to the constraints defined within the dataset. From here, you leveraged the Pivot tool to count status codes over time in 1-hour increments. This is like doing a | timechart span=1h count by status search at the end of a filtered search. Selecting to visualize this data in a line chart helps to easily identify the various status codes over time and can clearly illustrate error spikes or increases over a specific time.

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.