<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic line chart comparison between yesterday and todays data in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/line-chart-comparison-between-yesterday-and-todays-data/m-p/671686#M18110</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have requirement to show the line chart comparison between todays count vs previous day. And, I have below SPL but&amp;nbsp;&lt;SPAN&gt;we see the data from yesterday and today, and each graph line is separate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;I want to see the lines together, one superimposed on the other. please could you suggest?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="selvam_sekar_2-1702462177610.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28480iE18E69BA6CA34144/image-size/medium?v=v2&amp;amp;px=400" role="button" title="selvam_sekar_2-1702462177610.png" alt="selvam_sekar_2-1702462177610.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please can you suggest to compare them?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Current SPL:&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;basesearch earliest=-1d@d latest=now&lt;BR /&gt;| eval Day=if(_time&amp;lt;relative_time(now(),"@d"),"Yesterday","Today")&lt;BR /&gt;| timechart span=15m count by Day&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Current visualization:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="selvam_sekar_0-1702461940437.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28478i713DB272CAEECCAF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="selvam_sekar_0-1702461940437.png" alt="selvam_sekar_0-1702461940437.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Expected visualization&amp;nbsp;is:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="selvam_sekar_1-1702462074024.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28479i2F82D9A4445C5346/image-size/medium?v=v2&amp;amp;px=400" role="button" title="selvam_sekar_1-1702462074024.png" alt="selvam_sekar_1-1702462074024.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2023 10:11:15 GMT</pubDate>
    <dc:creator>selvam_sekar</dc:creator>
    <dc:date>2023-12-13T10:11:15Z</dc:date>
    <item>
      <title>line chart comparison between yesterday and todays data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/line-chart-comparison-between-yesterday-and-todays-data/m-p/671686#M18110</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have requirement to show the line chart comparison between todays count vs previous day. And, I have below SPL but&amp;nbsp;&lt;SPAN&gt;we see the data from yesterday and today, and each graph line is separate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;I want to see the lines together, one superimposed on the other. please could you suggest?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="selvam_sekar_2-1702462177610.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28480iE18E69BA6CA34144/image-size/medium?v=v2&amp;amp;px=400" role="button" title="selvam_sekar_2-1702462177610.png" alt="selvam_sekar_2-1702462177610.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please can you suggest to compare them?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Current SPL:&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;basesearch earliest=-1d@d latest=now&lt;BR /&gt;| eval Day=if(_time&amp;lt;relative_time(now(),"@d"),"Yesterday","Today")&lt;BR /&gt;| timechart span=15m count by Day&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Current visualization:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="selvam_sekar_0-1702461940437.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28478i713DB272CAEECCAF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="selvam_sekar_0-1702461940437.png" alt="selvam_sekar_0-1702461940437.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Expected visualization&amp;nbsp;is:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="selvam_sekar_1-1702462074024.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28479i2F82D9A4445C5346/image-size/medium?v=v2&amp;amp;px=400" role="button" title="selvam_sekar_1-1702462074024.png" alt="selvam_sekar_1-1702462074024.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 10:11:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/line-chart-comparison-between-yesterday-and-todays-data/m-p/671686#M18110</guid>
      <dc:creator>selvam_sekar</dc:creator>
      <dc:date>2023-12-13T10:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: line chart comparison between yesterday and todays data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/line-chart-comparison-between-yesterday-and-todays-data/m-p/671698#M18111</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;have you look &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Timewrap" target="_self"&gt;timewrap&lt;/A&gt; command?&lt;/P&gt;&lt;P&gt;You could try something like&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;basesearch earliest=-1d@d latest=now
| timechart span=15m count
| timewrap d &lt;/LI-CODE&gt;&lt;P&gt;Your result shows little bit weird as yesterday you have a whole day, but today is only from midnight to now.&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 11:01:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/line-chart-comparison-between-yesterday-and-todays-data/m-p/671698#M18111</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-12-13T11:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: line chart comparison between yesterday and todays data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/line-chart-comparison-between-yesterday-and-todays-data/m-p/671765#M18119</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;. How do we get the comparison between today vs yesterday with some time line.&lt;/P&gt;
&lt;P&gt;Currently I am getting yesterday whole day(24 hrs) but today midnight to upto now.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is it possible for us to bring only today (midnight till now) vs same timeframe previous day in the chart?&lt;/P&gt;
&lt;P&gt;Current SPL:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;basesearch earliest=-1d@d latest=now
| timechart span=1h count
| timewrap d series=short
| fields _time s1 s0
| rename s1 as today, s0 as yesterday&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 13 Dec 2023 17:00:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/line-chart-comparison-between-yesterday-and-todays-data/m-p/671765#M18119</guid>
      <dc:creator>selvam_sekar</dc:creator>
      <dc:date>2023-12-13T17:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: line chart comparison between yesterday and todays data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/line-chart-comparison-between-yesterday-and-todays-data/m-p/671768#M18120</link>
      <description>&lt;P&gt;Maybe not exactly what you are looking, but at least you could cleared out (set to 0) those events like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;basesearch earliest=-1d@d latest=now
| eval takeIn = case (_time&amp;gt;=relative_time(now(),"@d") ,"take",
                      _time&amp;lt;=relative_time(now(), "-1d"), "take",
                      true(), "drop")
| where takeIn = "take"
| timechart span=1h count
| timewrap d series=short
| fields _time s1 s0
| rename s1 as today, s0 as yesterday&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 13 Dec 2023 17:20:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/line-chart-comparison-between-yesterday-and-todays-data/m-p/671768#M18120</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-12-13T17:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: line chart comparison between yesterday and todays data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/line-chart-comparison-between-yesterday-and-todays-data/m-p/672028#M18141</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;. This works as expected &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; and only thing is not grouping the the user_id but rather it's grouping by timeformat/_time every 1 hr.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is it possible to group by user_id?&lt;/P&gt;
&lt;P&gt;current spl:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;base search | rex user_id

| eval takeIn = case (_time&amp;gt;=relative_time(now(),"@d") ,"take",
_time&amp;lt;=relative_time(now(), "-1d"), "take",
true(), "drop")
| where takeIn = "take"
| timechart span=1h count
| timewrap d series=short
| fields _time s1 s0 
| rename s1 as today, s0 as yesterday | where today !=""&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 15 Dec 2023 15:29:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/line-chart-comparison-between-yesterday-and-todays-data/m-p/672028#M18141</guid>
      <dc:creator>selvam_sekar</dc:creator>
      <dc:date>2023-12-15T15:29:16Z</dc:date>
    </item>
  </channel>
</rss>

