<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to merge two dashboards into one? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382125#M25024</link>
    <description>&lt;P&gt;As well as _time, you have two different dimensions, the instance number and the various readings, so you're probably better off just putting two separate panels on the same dash.  Timechart doesn't handle multiple dimensions that well, so you'd end up with the individual lines being "instance1 - cpu", "instance2 - cpu" and so on, which isn't very readable.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Aug 2018 15:57:57 GMT</pubDate>
    <dc:creator>DalJeanis</dc:creator>
    <dc:date>2018-08-01T15:57:57Z</dc:date>
    <item>
      <title>How to merge two dashboards into one?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382123#M25022</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;There are two graphs, each showing status of two instances. I wanted to merge both graphs into one. &lt;BR /&gt;
Both have the same source type and index. Can anyone suggest on this?&lt;/P&gt;

&lt;P&gt;Thanks &lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5468i5075CCDF8E93844C/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 11:55:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382123#M25022</guid>
      <dc:creator>swetar</dc:creator>
      <dc:date>2018-08-01T11:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge two dashboards into one?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382124#M25023</link>
      <description>&lt;P&gt;Please provide the searches for the graphs and we can try to help you merge them.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 13:17:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382124#M25023</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-08-01T13:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge two dashboards into one?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382125#M25024</link>
      <description>&lt;P&gt;As well as _time, you have two different dimensions, the instance number and the various readings, so you're probably better off just putting two separate panels on the same dash.  Timechart doesn't handle multiple dimensions that well, so you'd end up with the individual lines being "instance1 - cpu", "instance2 - cpu" and so on, which isn't very readable.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 15:57:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382125#M25024</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2018-08-01T15:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge two dashboards into one?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382126#M25025</link>
      <description>&lt;P&gt;Thanks for your reply. I was able to merge both the chart in the following way..&lt;BR /&gt;
SPL side# Sourcetype1  appendcols  [search sourcetype2&lt;BR /&gt;
then I used &lt;STRONG&gt;chart overlay&lt;/STRONG&gt; to overlap both of them.&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5467i740E8895CDCF7C6B/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 02:44:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382126#M25025</guid>
      <dc:creator>swetar</dc:creator>
      <dc:date>2018-08-08T02:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge two dashboards into one?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382127#M25026</link>
      <description>&lt;P&gt;@swetar, If your problem is resolved, please accept the answer to help future readers.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 09:59:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382127#M25026</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-08-08T09:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge two dashboards into one?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382128#M25027</link>
      <description>&lt;P&gt;@swetar - &lt;CODE&gt;appendcols&lt;/CODE&gt; is going to fail the moment that either query returns a different number of results.  If you provide the underlying searches, then we can help you merge them in a way that will work in all scenarios.&lt;/P&gt;

&lt;P&gt;In general, you want to aim for &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index=foo1 sourcetype=bar whatever other search terms)
OR
(index=foo2 sourcetype=baz whatever other search terms)
| fields  ... list all the fields you want to keep ...
| eval fields1 = create  any fields you need to calculate 
| timechart span=15m 
  count as nameOfFirstLine
  sum(somefield) as nameOfSecondLine    
  aggregatefunction(fields) as nameOfThirdLine
  aggregatefunction(fields) as nameOfFourthLine
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The above should work under all cases,as  long as the aggregate functions are operating on fields that will only be in the relevant events.  You can control that either by building new fields that only exist on the right kind of record, or by using an eval in the aggregate function... which is an advanced method of coding that you may want to avoid for now.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 18:34:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382128#M25027</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2018-08-08T18:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge two dashboards into one?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382129#M25028</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/203121"&gt;@DalJeanis&lt;/a&gt;  I m using the below SPL and its working fine ..:)&lt;/P&gt;

&lt;P&gt;sourcetype="oracle_sourcetype1XXXXXX" | eval V_INST_NAME= case(INST_ID=="1","test1",INST_ID=="2","test2") &lt;BR /&gt;
    | where like (V_INST_NAME,"%")&lt;BR /&gt;
|timechart span=10m first(P_COUNT) as PQ by INST_ID |rename 1 as "Parallel Count for test1" 2 as "Parallel Count for test2" &lt;BR /&gt;
| filldown &lt;BR /&gt;
|  appendcols &lt;BR /&gt;
    [search sourcetype = oracle_sourcetype2YYYYYYY | eval V_INST_NAME= case(INST_ID=="1","test1",INST_ID=="2","test2")  |where like (V_INST_NAME,"%") &lt;BR /&gt;
| timechart span=10m first(SESSIONS_COUNT) as sessions_count by INST_ID &lt;BR /&gt;
| rename 1 as "Session Count for test1" 2 as "Session Count for test2"&lt;BR /&gt;
| filldown ]&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:49:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-merge-two-dashboards-into-one/m-p/382129#M25028</guid>
      <dc:creator>swetar</dc:creator>
      <dc:date>2020-09-29T20:49:36Z</dc:date>
    </item>
  </channel>
</rss>

