Hi, splunk comunity!
How can i make query which print some info in column chart filtred by hosts and also upper bound line?
I try to do something like this:
....
| eval top=some logic to calculate top value
| timechart sum(someInfo) as "counter" max(top) as "upper bound" by host
....
but i have columns which contains value of upper bound for each host, but not an upper bound line
I believe you are looking for a chart overlay. Check out this page: Chart overlay example (dual axis).
So edit your column chart by clicking on "Format", then on "Chart Overlay" and then select the "upper bound" field.
@mishaaaaaaaaaa
Can you please explain the requirement again with any snippet if you have?