<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: a very simple query with two data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/a-very-simple-query-with-two-data/m-p/515688#M144800</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225345"&gt;@rpachecoa&lt;/a&gt;&amp;nbsp;, assuming execution date field name as execution_date and avg execution time as avg_exec_time and process name as process&lt;/P&gt;&lt;P&gt;......| chart values(&lt;SPAN&gt;avg_exec_time) by process over execution_date&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;please upvote if it helps!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Aug 2020 05:43:48 GMT</pubDate>
    <dc:creator>Nisha18789</dc:creator>
    <dc:date>2020-08-24T05:43:48Z</dc:date>
    <item>
      <title>a very simple query with two data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/a-very-simple-query-with-two-data/m-p/515680#M144795</link>
      <description>&lt;P&gt;hello Guys,&lt;/P&gt;&lt;P&gt;I'm very very noob using Splunk,&amp;nbsp;&lt;SPAN&gt;I have a very simple log file&amp;nbsp; which contains 5 columns of data:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;bloque1 | 2020-04-01| 05:39:35.407 | 09:14:34.398 | 03:34:58.991&lt;BR /&gt;bloque1 | 2020-04-02| 03:50:29.469 | 07:26:32.869 | 03:36:03.4&lt;BR /&gt;bloque1 | 2020-04-03| 04:09:47.659 | 08:05:38.248 | 03:55:50.589&lt;BR /&gt;bloque1 | 2020-04-04| 04:49:51.142 | 08:37:40.141 | 03:47:48.999&lt;BR /&gt;bloque1 | 2020-04-05| 05:27:43.616 | 09:06:23.898 | 03:38:40.282&lt;BR /&gt;bloque1 | 2020-04-06| 06:51:08.264 | 10:27:12.113 | 03:36:03.849&lt;BR /&gt;bloque1 | 2020-04-07| 04:05:32.292 | 07:54:32.055 | 03:48:59.763&lt;/P&gt;&lt;P&gt;etc, &lt;SPAN&gt;I am trying to graph the second field with the last field.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The second field is the day of execution of a process and the last field is the average execution time&amp;nbsp; of that process.&amp;nbsp; I just want a graph that places the value of the execution date on "x" axis and the average time per day on the "y" Axis.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I only get a straight line graph with the event count per day.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could you help me with the query or the necessary steps to be able to obtain the graph I want. I greatly appreciate the support and your comments.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 04:13:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/a-very-simple-query-with-two-data/m-p/515680#M144795</guid>
      <dc:creator>rpachecoa</dc:creator>
      <dc:date>2020-08-24T04:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: a very simple query with two data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/a-very-simple-query-with-two-data/m-p/515688#M144800</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225345"&gt;@rpachecoa&lt;/a&gt;&amp;nbsp;, assuming execution date field name as execution_date and avg execution time as avg_exec_time and process name as process&lt;/P&gt;&lt;P&gt;......| chart values(&lt;SPAN&gt;avg_exec_time) by process over execution_date&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;please upvote if it helps!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 05:43:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/a-very-simple-query-with-two-data/m-p/515688#M144800</guid>
      <dc:creator>Nisha18789</dc:creator>
      <dc:date>2020-08-24T05:43:48Z</dc:date>
    </item>
  </channel>
</rss>

