<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to achieve timechart query group by multiple fields? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-achieve-timechart-query-group-by-multiple-fields/m-p/642931#M222682</link>
    <description>&lt;P&gt;The simplest way is to do&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;query |
| rex field=event "'job_name': '(?&amp;lt;job_name&amp;gt;.+?)',"
| rex field=event "'job_status': '(?&amp;lt;job_status&amp;gt;.+?)',"
| eval series=job_name.":".job_status
| timechart count by series&lt;/LI-CODE&gt;</description>
    <pubDate>Wed, 10 May 2023 22:39:08 GMT</pubDate>
    <dc:creator>bowesmana</dc:creator>
    <dc:date>2023-05-10T22:39:08Z</dc:date>
    <item>
      <title>How to achieve timechart query group by multiple fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-achieve-timechart-query-group-by-multiple-fields/m-p/642854#M222649</link>
      <description>&lt;P&gt;Hi, I am trying to create a line graph where I want to show job status overtime. So I want 1 line for failed and another for passed jobs.&lt;/P&gt;
&lt;P&gt;query |&lt;BR /&gt;| rex field=event "'job_name': '(?&amp;lt;job_name&amp;gt;.+?)',"&lt;BR /&gt;| rex field=event "'job_status': '(?&amp;lt;job_status&amp;gt;.+?)',"&lt;BR /&gt;| timechart count by job_status&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Above query is grouping by staus all jobs together. I want to split the status by jobs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 17:08:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-achieve-timechart-query-group-by-multiple-fields/m-p/642854#M222649</guid>
      <dc:creator>splunkuser320</dc:creator>
      <dc:date>2023-05-10T17:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to achieve timechart query group by multiple fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-achieve-timechart-query-group-by-multiple-fields/m-p/642931#M222682</link>
      <description>&lt;P&gt;The simplest way is to do&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;query |
| rex field=event "'job_name': '(?&amp;lt;job_name&amp;gt;.+?)',"
| rex field=event "'job_status': '(?&amp;lt;job_status&amp;gt;.+?)',"
| eval series=job_name.":".job_status
| timechart count by series&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 10 May 2023 22:39:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-achieve-timechart-query-group-by-multiple-fields/m-p/642931#M222682</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-05-10T22:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to achieve timechart query group by multiple fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-achieve-timechart-query-group-by-multiple-fields/m-p/642933#M222684</link>
      <description>&lt;P&gt;If you watch&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/3514"&gt;@alacercogitatus&lt;/a&gt;' perennial .conf talk "Lesser Known Search Commands" , another way to achieve this, is through using eval to create fields named for other field values.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;For example:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex ... 
| eval JS_{job_status} = 1
| timechart count(JS_*) as * by job_name&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;Of course I'm assuming there's not many potential values to job_status, or else, oof, that could be a bit brutal for the number of fields...&amp;nbsp; and you can use this trick with any other statistical function here as well...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 00:19:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-achieve-timechart-query-group-by-multiple-fields/m-p/642933#M222684</guid>
      <dc:creator>acharlieh</dc:creator>
      <dc:date>2023-05-11T00:19:04Z</dc:date>
    </item>
  </channel>
</rss>

