Dashboards & Visualizations

Adding overlay to timechart

ILLLLM
New Member

 

source=*.log host=myhostname "provider=microsoft" "status=SENT_TO_AGENT" | timechart dedup_splitvals=t limit=10 useother=t count AS "Count of Event Object" by provider format=$VAL$:::$AGG$ | fields + _time, "*"

 


This will display a count of entries in the logs that say "SENT_TO_AGENT"

I want to display an average line chart for previous 3 months, and the current month as an overlay over the previous months. 

Labels (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What does your timechart currently give you? Daily counts, hourly counts? What does "average" mean in this context? Does previous 3 months include the current month or only complete months prior to the current month?

Please provide some sample representative anonymised events and a representation of what your output results would be (as a table not a graph).

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...