Dashboards & Visualizations

Adding overlay to timechart

ILLLLM
New Member

 

source=*.log host=myhostname "provider=microsoft" "status=SENT_TO_AGENT" | timechart dedup_splitvals=t limit=10 useother=t count AS "Count of Event Object" by provider format=$VAL$:::$AGG$ | fields + _time, "*"

 


This will display a count of entries in the logs that say "SENT_TO_AGENT"

I want to display an average line chart for previous 3 months, and the current month as an overlay over the previous months. 

Labels (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What does your timechart currently give you? Daily counts, hourly counts? What does "average" mean in this context? Does previous 3 months include the current month or only complete months prior to the current month?

Please provide some sample representative anonymised events and a representation of what your output results would be (as a table not a graph).

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...