<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple data series in line chart - dashboard visualization in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18667#M631</link>
    <description>&lt;P&gt;I am trying to display data in the form of line chart in dashboard. Each line in the chart should represent a separate series. For ex: one series would show number of events "string1" appears in index i1 and other series be number of events "string2" appears in the same index i1.&lt;/P&gt;

&lt;P&gt;For one data series I can write in the search bar something like:&lt;/P&gt;

&lt;P&gt;index = i1 string1 | timechart count by event &lt;/P&gt;

&lt;P&gt;How can I incorporate string 2 in this such that for each string the count of events in which the strings appear can be represented by two different lines in a chart in dashboard?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jul 2012 18:44:14 GMT</pubDate>
    <dc:creator>parth_jec</dc:creator>
    <dc:date>2012-07-26T18:44:14Z</dc:date>
    <item>
      <title>Multiple data series in line chart - dashboard visualization</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18667#M631</link>
      <description>&lt;P&gt;I am trying to display data in the form of line chart in dashboard. Each line in the chart should represent a separate series. For ex: one series would show number of events "string1" appears in index i1 and other series be number of events "string2" appears in the same index i1.&lt;/P&gt;

&lt;P&gt;For one data series I can write in the search bar something like:&lt;/P&gt;

&lt;P&gt;index = i1 string1 | timechart count by event &lt;/P&gt;

&lt;P&gt;How can I incorporate string 2 in this such that for each string the count of events in which the strings appear can be represented by two different lines in a chart in dashboard?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2012 18:44:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18667#M631</guid>
      <dc:creator>parth_jec</dc:creator>
      <dc:date>2012-07-26T18:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple data series in line chart - dashboard visualization</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18668#M632</link>
      <description>&lt;P&gt;Updated:&lt;/P&gt;

&lt;P&gt;The docs had been updated and I don't have the exact page but here are some references:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.4/SearchReference/Timechart#Example_5"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.4/SearchReference/Timechart#Example_5&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/5990/multiple-series-line-chart-dashboard"&gt;http://answers.splunk.com/answers/5990/multiple-series-line-chart-dashboard&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/55032/multi-line-graph-from-multiple-hosts"&gt;http://answers.splunk.com/answers/55032/multi-line-graph-from-multiple-hosts&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2012 19:06:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18668#M632</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-07-26T19:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple data series in line chart - dashboard visualization</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18669#M633</link>
      <description>&lt;P&gt;Thanks for the link. I checked it but I am not getting clearly how its done. &lt;/P&gt;

&lt;P&gt;I want to search for multiple strings in an index, calculate count of events separately in which the strigs appear and then plot them in a chart. &lt;/P&gt;

&lt;P&gt;The example in the link does not show how can I search for a string and plot it in chart. Ex: index = i1 string1 "String 1 " | stats count &lt;BR /&gt;
This will give the number events in index i1 where "String 1" is present. How can implement this using the example given in the link?&lt;BR /&gt;
Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2012 21:37:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18669#M633</guid>
      <dc:creator>parth_jec</dc:creator>
      <dc:date>2012-07-26T21:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple data series in line chart - dashboard visualization</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18670#M634</link>
      <description>&lt;P&gt;I think what you want is multiple stats operations...one for each field.  Or maybe i'm missing something?&lt;/P&gt;

&lt;P&gt;... | stats count(field1) count(field2) avg(field3)&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2012 01:48:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18670#M634</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-07-27T01:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple data series in line chart - dashboard visualization</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18671#M635</link>
      <description>&lt;P&gt;do I have to create fields for each of the string I want to search (string1, string2) first?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2012 16:28:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18671#M635</guid>
      <dc:creator>parth_jec</dc:creator>
      <dc:date>2012-07-27T16:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple data series in line chart - dashboard visualization</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18672#M636</link>
      <description>&lt;P&gt;Yes, you'll need fields for those values you want to count.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2012 16:32:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18672#M636</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-07-27T16:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple data series in line chart - dashboard visualization</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18673#M637</link>
      <description>&lt;P&gt;I am trying to create field (key/value) pairs for string1 and string2 interactively following &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/ExtractfieldsinteractivelywithIFX"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/ExtractfieldsinteractivelywithIFX&lt;/A&gt;&lt;BR /&gt;
For string1 I am able to create a field but for string2 splunk is not allowing me to create field, it does not creates regex for the second string, is there another way to create fields? Also, I was wondering since I know there will be only one value associated with each of the fields I create, is creating fields the only way to do it? ex: field s1="String1" and s2="String2" always.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2012 20:31:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18673#M637</guid>
      <dc:creator>parth_jec</dc:creator>
      <dc:date>2012-07-27T20:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple data series in line chart - dashboard visualization</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18674#M638</link>
      <description>&lt;P&gt;Is it just me or do none of these links work??? What am I doing wrong?  It brings me to a page that says only this is a special page...&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2013 12:47:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18674#M638</guid>
      <dc:creator>benspader</dc:creator>
      <dc:date>2013-08-21T12:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple data series in line chart - dashboard visualization</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18675#M639</link>
      <description>&lt;P&gt;You are correct.  Updating now.  Looks like references were changed in the online docs.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2013 13:22:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18675#M639</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2013-08-21T13:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple data series in line chart - dashboard visualization</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18676#M640</link>
      <description>&lt;P&gt;Multiline data series not working with Splunk . I tried a simple timchart count by host and dashboard is not supporting this query. When I schedule pdf delivery it just shows as blank.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2013 07:34:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18676#M640</guid>
      <dc:creator>arungeorge09</dc:creator>
      <dc:date>2013-09-06T07:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple data series in line chart - dashboard visualization</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18677#M641</link>
      <description>&lt;P&gt;Sounds like you need  to post a new question with your specific challenge.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2013 11:39:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-data-series-in-line-chart-dashboard-visualization/m-p/18677#M641</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2013-09-06T11:39:44Z</dc:date>
    </item>
  </channel>
</rss>

