<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Select my extracted fields for correlation in timechart in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94591#M24415</link>
    <description>&lt;P&gt;Uh...well yes. That's kind of basic search filtering functionality. If you're unsure about those kind of things I advise you to take the Splunk tutorial.&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jul 2013 12:49:21 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2013-07-15T12:49:21Z</dc:date>
    <item>
      <title>Select my extracted fields for correlation in timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94581#M24405</link>
      <description>&lt;P&gt;I am using a search command of sourcetype=CurrentWeatherSGMap OR sourcetype=ltaTraffic  |  timechart count(type) as Incident count(current_summary) as Rain.&lt;/P&gt;

&lt;P&gt;I had current_summary and type, which I needed only the Rain from current_summary and Accident from type in both sources using the search query. Anyway I can do it ?&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/Untitledtweayher_1.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/Untitledtraffic_1.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:20:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94581#M24405</guid>
      <dc:creator>sbnoobbb</dc:creator>
      <dc:date>2020-09-28T14:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: Select my extracted fields for correlation in timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94582#M24406</link>
      <description>&lt;P&gt;xmlkv is used for performing field extraction on certain XML formatted data. Not sure how it would be relevant in your scenario.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2013 08:12:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94582#M24406</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-07-15T08:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Select my extracted fields for correlation in timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94583#M24407</link>
      <description>&lt;P&gt;I have edited the question. Check it out &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2013 08:40:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94583#M24407</guid>
      <dc:creator>sbnoobbb</dc:creator>
      <dc:date>2013-07-15T08:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Select my extracted fields for correlation in timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94584#M24408</link>
      <description>&lt;P&gt;OK, but I have no idea what your desired result is (same issue as in your partner's more or less identical question). What exactly are you trying to do? What is the desired end result?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2013 09:09:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94584#M24408</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-07-15T09:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: Select my extracted fields for correlation in timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94585#M24409</link>
      <description>&lt;P&gt;I wanted to do a search for Rain and Accident on a timechart showing how rain affects more accidents (correlation of weather and traffic accidents). However the Accident is in Type and Rain is in current_summary. I need to do a count for number of times it rains on a specific location then count for accidents on the same location then plot it on a timechart.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2013 09:56:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94585#M24409</guid>
      <dc:creator>sbnoobbb</dc:creator>
      <dc:date>2013-07-15T09:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Select my extracted fields for correlation in timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94586#M24410</link>
      <description>&lt;P&gt;So the desired result would be a graph with two lines - one for occurrences of rain and one for occurrences of accidents?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2013 10:16:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94586#M24410</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-07-15T10:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Select my extracted fields for correlation in timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94587#M24411</link>
      <description>&lt;P&gt;Yes !  Against the same location !&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2013 11:22:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94587#M24411</guid>
      <dc:creator>kailun92</dc:creator>
      <dc:date>2013-07-15T11:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: Select my extracted fields for correlation in timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94588#M24412</link>
      <description>&lt;P&gt;Did you read the timechart docs? You can specify which field values you are interested in using eval statements. So something like this should work:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=CurrentWeatherSGMap OR sourcetype=ltaTraffic | timechart count(eval(type=="Accident")) as Incident, count(eval(current_summary=="Rain")) as Rain
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 15 Jul 2013 12:33:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94588#M24412</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-07-15T12:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Select my extracted fields for correlation in timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94589#M24413</link>
      <description>&lt;P&gt;What if i got another field called location and I need the location of "PIE" for example?  Only display result for PIE, how can i do that ? Put at by location=PIE ?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2013 12:39:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94589#M24413</guid>
      <dc:creator>kailun92</dc:creator>
      <dc:date>2013-07-15T12:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: Select my extracted fields for correlation in timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94590#M24414</link>
      <description>&lt;P&gt;Consider that both sourcetype have these location fields extracted.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2013 12:42:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94590#M24414</guid>
      <dc:creator>kailun92</dc:creator>
      <dc:date>2013-07-15T12:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Select my extracted fields for correlation in timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94591#M24415</link>
      <description>&lt;P&gt;Uh...well yes. That's kind of basic search filtering functionality. If you're unsure about those kind of things I advise you to take the Splunk tutorial.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2013 12:49:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94591#M24415</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-07-15T12:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Select my extracted fields for correlation in timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94592#M24416</link>
      <description>&lt;P&gt;Kk, i am just double checking &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt; I am only not sure about the two sourcetype. Thanks !  Eval is what i needed &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2013 12:57:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-my-extracted-fields-for-correlation-in-timechart/m-p/94592#M24416</guid>
      <dc:creator>kailun92</dc:creator>
      <dc:date>2013-07-15T12:57:53Z</dc:date>
    </item>
  </channel>
</rss>

