<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Area Chart - Dashboard in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Area-Chart-Dashboard/m-p/694000#M56826</link>
    <description>&lt;P&gt;Query1:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|tstats count as Requests sum(attributes.ResponseTime) as TotalResponseTime where index=app-index NOT attributes.uriPath("/", null, "/provider") 
|eval TotResTime=TotalResponseTime/Requests
|fields TotResTime&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Query2:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|tstats count as Requests sum(attributes.latencyTime) as TotalatcyTime where index=app-index NOT attributes.uriPath("/", null, "/provider") 
|eval TotlatencyTime=TotalatcyTime/Requests
|fields TotlatencyTime&lt;/LI-CODE&gt;&lt;P&gt;We want to combine these 2 queries and create area chart panel.&amp;nbsp;&lt;/P&gt;&lt;P&gt;how to do this??&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jul 2024 19:32:21 GMT</pubDate>
    <dc:creator>Ram2</dc:creator>
    <dc:date>2024-07-22T19:32:21Z</dc:date>
    <item>
      <title>Area Chart - Dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Area-Chart-Dashboard/m-p/694000#M56826</link>
      <description>&lt;P&gt;Query1:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|tstats count as Requests sum(attributes.ResponseTime) as TotalResponseTime where index=app-index NOT attributes.uriPath("/", null, "/provider") 
|eval TotResTime=TotalResponseTime/Requests
|fields TotResTime&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Query2:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|tstats count as Requests sum(attributes.latencyTime) as TotalatcyTime where index=app-index NOT attributes.uriPath("/", null, "/provider") 
|eval TotlatencyTime=TotalatcyTime/Requests
|fields TotlatencyTime&lt;/LI-CODE&gt;&lt;P&gt;We want to combine these 2 queries and create area chart panel.&amp;nbsp;&lt;/P&gt;&lt;P&gt;how to do this??&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 19:32:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Area-Chart-Dashboard/m-p/694000#M56826</guid>
      <dc:creator>Ram2</dc:creator>
      <dc:date>2024-07-22T19:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: Area Chart - Dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Area-Chart-Dashboard/m-p/694051#M56832</link>
      <description>&lt;P&gt;Putting the queries together is pretty simple, but getting a usable graph from the result is another matter.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats count as Requests sum(attributes.ResponseTime) as TotalResponseTime sum(attributes.latencyTime) as TotalatcyTime where index=app-index NOT attributes.uriPath("/", null, "/provider") 
| eval TotResTime=TotalResponseTime/Requests, TotlatencyTime=TotalatcyTime/Requests
| fields TotResTime TotlatencyTime&lt;/LI-CODE&gt;&lt;P&gt;This will produce two single-value fields, which isn't enough for an area chart.&amp;nbsp; What is it you want to show in the chart?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 12:09:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Area-Chart-Dashboard/m-p/694051#M56832</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-07-23T12:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Area Chart - Dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Area-Chart-Dashboard/m-p/694059#M56833</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;, I want to show the total data coming from each query by _time in area chart.&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;When we run 1st query i will get output as 100.0789, I want to show this same output as _time in area chart.&lt;BR /&gt;I mean to say i want to split this 100.0789 by _time and shown it in area graph.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 13:28:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Area-Chart-Dashboard/m-p/694059#M56833</guid>
      <dc:creator>Ram2</dc:creator>
      <dc:date>2024-07-23T13:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: Area Chart - Dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Area-Chart-Dashboard/m-p/694063#M56834</link>
      <description>&lt;P&gt;To graph data over time requires the _time field and a charting command.&amp;nbsp; Usually, I use &lt;FONT face="courier new,courier"&gt;timechart&lt;/FONT&gt;, but it only supports a single field so this query uses &lt;FONT face="courier new,courier"&gt;chart&lt;/FONT&gt;.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats count as Requests sum(attributes.ResponseTime) as TotalResponseTime sum(attributes.latencyTime) as TotalatcyTime where index=app-index NOT attributes.uriPath("/", null, "/provider") by _time span=1d
| eval TotResTime=TotalResponseTime/Requests, TotlatencyTime=TotalatcyTime/Requests
| chart max(TotResTime) as TotResTime, max(TotlatencyTime) as TotlatencyTime over _time&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 23 Jul 2024 14:06:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Area-Chart-Dashboard/m-p/694063#M56834</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-07-23T14:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Area Chart - Dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Area-Chart-Dashboard/m-p/694091#M56835</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;, thank you so much it worked&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 18:04:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Area-Chart-Dashboard/m-p/694091#M56835</guid>
      <dc:creator>Ram2</dc:creator>
      <dc:date>2024-07-23T18:04:54Z</dc:date>
    </item>
  </channel>
</rss>

