All Apps and Add-ons

Overlay two time based grouped results in a Chart

lslschr
Engager

 

 

 

 

index=xy device_event_class_id=Bandwidth earliest=-1d@d latest=-0d@d  
| rex field=msg "msg=.+raffic.+'(?<pg_name>[\w\s\-]+)'.+(?<bps>\d+\.\d+\s.+)\..+"   
| eval ReportKey="yersterday" 
| timechart span=3h count by pg_name 
| append [search index=xy device_event_class_id=Bandwidth earliest=-2d@d latest=-1d@d 
| rex field=msg "msg=.+raffic.+'(?<pg_name>[\w\s\-]+)'.+(?<bps>\d+\.\d+\s.+)\..+"   
| eval ReportKey="beforeyesterday" 
| timechart span=3h count by pg_name  ] 
| fillnull value=0 
| eval mytime=strftime(_time, "%H:%M") 
| sort mytime

 

 

 

 

I'm trying to create a chart containing two timecharts for different time frames (today/yesterday). How can I achieve it?
Currently I'm getting it one after another. I'd like basically to overlay one timechart on another one.

lslschr_0-1618497785138.png

 

 

Labels (3)
0 Karma

ITWhisperer
Legend

This was answered here 

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.