<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Chart multiple series in Splunk 7.3: what's new? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Chart-multiple-series-in-Splunk-7-3-what-s-new/m-p/423636#M74396</link>
    <description>&lt;P&gt;This does not allow you to chart on multiple metric in single panel. &lt;BR /&gt;
It only allows one metric per panel and it creates separate panel for each metric. &lt;BR /&gt;
split by only allows to select dimension field for that also you can use only one dimension. &lt;/P&gt;

&lt;P&gt;I am looking for to chart multiple metrics in a single panel. &lt;BR /&gt;
I can do that using event data index but not with metrics index. &lt;BR /&gt;
is there a way to do it?&lt;BR /&gt;
Also metrics data index does not allow you to chart out of raw metric data. you have to use avg, max, min etc. mstat funtion.&lt;BR /&gt;
is there a way for that too?&lt;/P&gt;</description>
    <pubDate>Thu, 12 Sep 2019 21:34:01 GMT</pubDate>
    <dc:creator>patelmc</dc:creator>
    <dc:date>2019-09-12T21:34:01Z</dc:date>
    <item>
      <title>Chart multiple series in Splunk 7.3: what's new?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Chart-multiple-series-in-Splunk-7-3-what-s-new/m-p/423633#M74393</link>
      <description>&lt;P&gt;The &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/ReleaseNotes"&gt;Splunk 7.3 release notes&lt;/A&gt; describe the following "what's new" item:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Chart multiple series&lt;/STRONG&gt;&lt;BR /&gt;
Co-analyze multiple related metrics easily in the same view and create sophisticated visualizations for monitoring.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;According to the Splunk 7.3.1 documentation topic "&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/Search/Chartmultipledataseries"&gt;Build a chart of multiple data series&lt;/A&gt;":&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Splunk transforming commands do not support a direct way to define multiple data series in your charts (or timecharts). However, you CAN achieve this using a combination of the stats and xyseries commands."&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I've read that topic before, in previous Splunk versions, and have used the techniques it describes.&lt;/P&gt;

&lt;P&gt;So, I'm curious: &lt;STRONG&gt;what is &lt;EM&gt;actually new&lt;/EM&gt; about this item for 7.3?&lt;/STRONG&gt; Does it refer to some new feature in SPL?&lt;/P&gt;

&lt;P&gt;Or—noting the reference to, or qualification, &lt;EM&gt;metrics&lt;/EM&gt; in that 7.3 "what's new" item—perhaps what's new here is a new feature in the Metrics Workspace, which generates SPL that uses the techniques in that "Build a chart of multiple data series"?&lt;/P&gt;

&lt;P&gt;Confession: I dip in and out of Splunk every so often. I've read about metrics and the Metrics Workspace, but not yet used them. So far, I've only used &lt;EM&gt;events&lt;/EM&gt; with SPL and Simple XML to develop dashboards.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 04:55:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Chart-multiple-series-in-Splunk-7-3-what-s-new/m-p/423633#M74393</guid>
      <dc:creator>Graham_Hanningt</dc:creator>
      <dc:date>2019-08-01T04:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: Chart multiple series in Splunk 7.3: what's new?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Chart-multiple-series-in-Splunk-7-3-what-s-new/m-p/423634#M74394</link>
      <description>&lt;P&gt;This question is something best submitted as feedback on the relevant documentation page(s).  The Docs team is excellent about using feedback like this (not from Answers) to clarify the documentation.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 13:24:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Chart-multiple-series-in-Splunk-7-3-what-s-new/m-p/423634#M74394</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-08-01T13:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Chart multiple series in Splunk 7.3: what's new?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Chart-multiple-series-in-Splunk-7-3-what-s-new/m-p/423635#M74395</link>
      <description>&lt;P&gt;@Graham_Hannington I think you missed an very crucial part of information in the Splunk Documentation...&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Co-analyze multiple related &lt;CODE&gt;metrics&lt;/CODE&gt;&lt;/STRONG&gt; as this feature is specifically for Metrics Index data through &lt;CODE&gt;Metrics Workspace&lt;/CODE&gt; which comes &lt;CODE&gt;pre-installed with 7.3&lt;/CODE&gt;. For prior 7x version you needed to install &lt;A href="https://splunkbase.splunk.com/app/4192/"&gt;Metrics Workspace&lt;/A&gt; app separately from Splunkbase for this.&lt;/P&gt;

&lt;P&gt;What you can try is suffix &lt;CODE&gt;analysis_worspace&lt;/CODE&gt; in the URL besides your App and you should see Metrics work-space.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  &lt;A href="https://&amp;lt;yourSplunkURL&amp;gt;/en-US/app/&amp;lt;yourAppName&amp;gt;/analysis_workspace" target="test_blank"&gt;https://&amp;lt;yourSplunkURL&amp;gt;/en-US/app/&amp;lt;yourAppName&amp;gt;/analysis_workspace&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;PS: This will work only on Metrics Index data.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I would also recommend you to search Splunkbase for Splunk Essentials App for specific latest release of Splunk to get examples of new features introduced in the same.&lt;/P&gt;

&lt;P&gt;Following is the link to &lt;A href="https://splunkbase.splunk.com/app/4516/"&gt;Splunk Essentials for Cloud and Enterprise 7.3&lt;/A&gt; for your reference. Please do try out and confirm.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://cdn.apps.splunk.com/media/public/screenshots/1e84bb40-87b7-11e9-bb24-064768afc4fa.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 13:59:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Chart-multiple-series-in-Splunk-7-3-what-s-new/m-p/423635#M74395</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2019-08-01T13:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: Chart multiple series in Splunk 7.3: what's new?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Chart-multiple-series-in-Splunk-7-3-what-s-new/m-p/423636#M74396</link>
      <description>&lt;P&gt;This does not allow you to chart on multiple metric in single panel. &lt;BR /&gt;
It only allows one metric per panel and it creates separate panel for each metric. &lt;BR /&gt;
split by only allows to select dimension field for that also you can use only one dimension. &lt;/P&gt;

&lt;P&gt;I am looking for to chart multiple metrics in a single panel. &lt;BR /&gt;
I can do that using event data index but not with metrics index. &lt;BR /&gt;
is there a way to do it?&lt;BR /&gt;
Also metrics data index does not allow you to chart out of raw metric data. you have to use avg, max, min etc. mstat funtion.&lt;BR /&gt;
is there a way for that too?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 21:34:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Chart-multiple-series-in-Splunk-7-3-what-s-new/m-p/423636#M74396</guid>
      <dc:creator>patelmc</dc:creator>
      <dc:date>2019-09-12T21:34:01Z</dc:date>
    </item>
  </channel>
</rss>

