<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hi, I am facing problem with multiple subqueries in timechart. it is not showing the value for _time field. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Hi-I-am-facing-problem-with-multiple-subqueries-in-timechart-it/m-p/145420#M40521</link>
    <description>&lt;P&gt;Try something like this&lt;/P&gt;

&lt;P&gt;index= idx1 sourcetype=src1 sender="abc" OR sender="xyz" | timechart count(eval(sender="abc") as res1  count(eval(sender="xyz") as res2 &lt;/P&gt;</description>
    <pubDate>Tue, 30 Sep 2014 12:03:03 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2014-09-30T12:03:03Z</dc:date>
    <item>
      <title>Hi, I am facing problem with multiple subqueries in timechart. it is not showing the value for _time field.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Hi-I-am-facing-problem-with-multiple-subqueries-in-timechart-it/m-p/145418#M40519</link>
      <description>&lt;P&gt;Query "index=idx1 sourcetype=src1 sender="xyz" | timechart count as res1" showing results properly, and &lt;/P&gt;

&lt;P&gt;Query "index=idx1 sourcetype=src1 sender="abc" | timechart count as res2" not showing any result.&lt;/P&gt;

&lt;P&gt;when I am trying to combine both the queries as below: &lt;BR /&gt;
index=idx1 sourcetype=src1 sender="xyz" | timechart count as res1 | appendcols [search index=idx1 sourcetype=src1 sender="abc" | timechart count as res2] | fillnull res1, res2&lt;/P&gt;

&lt;P&gt;it is giving result, but &lt;STRONG&gt;no value for _time field&lt;/STRONG&gt; .&lt;/P&gt;

&lt;P&gt;how I can get values for _time field.&lt;/P&gt;

&lt;P&gt;pls help me....&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 11:15:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Hi-I-am-facing-problem-with-multiple-subqueries-in-timechart-it/m-p/145418#M40519</guid>
      <dc:creator>toabhishek16</dc:creator>
      <dc:date>2014-09-30T11:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: Hi, I am facing problem with multiple subqueries in timechart. it is not showing the value for _time field.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Hi-I-am-facing-problem-with-multiple-subqueries-in-timechart-it/m-p/145419#M40520</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
Rather than appending the result&lt;/P&gt;

&lt;P&gt;just do the below&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=idx1 sourcetype=src1 OR sourcetype=src2|timechart count by sourcetype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
L&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 11:24:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Hi-I-am-facing-problem-with-multiple-subqueries-in-timechart-it/m-p/145419#M40520</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-09-30T11:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: Hi, I am facing problem with multiple subqueries in timechart. it is not showing the value for _time field.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Hi-I-am-facing-problem-with-multiple-subqueries-in-timechart-it/m-p/145420#M40521</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;

&lt;P&gt;index= idx1 sourcetype=src1 sender="abc" OR sender="xyz" | timechart count(eval(sender="abc") as res1  count(eval(sender="xyz") as res2 &lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 12:03:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Hi-I-am-facing-problem-with-multiple-subqueries-in-timechart-it/m-p/145420#M40521</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-09-30T12:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: Hi, I am facing problem with multiple subqueries in timechart. it is not showing the value for _time field.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Hi-I-am-facing-problem-with-multiple-subqueries-in-timechart-it/m-p/145421#M40522</link>
      <description>&lt;P&gt;Joined Query&lt;BR /&gt;
"index=idx1 sourcetype=src1 sender="xyz" OR sender="abc" | timechart count by sender&lt;/P&gt;

&lt;P&gt;This is significantly more efficent than the options above.  It makes a single pass in the index and sourcetype to pull the data and populates the chart.  Before you have to query the same data twice to pull information.  Then you have to join the two results before charting.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 15:27:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Hi-I-am-facing-problem-with-multiple-subqueries-in-timechart-it/m-p/145421#M40522</guid>
      <dc:creator>ltrand</dc:creator>
      <dc:date>2014-09-30T15:27:11Z</dc:date>
    </item>
  </channel>
</rss>

