Dashboards & Visualizations

Create single stacked time chart for different fields for different fields

pranaynanda
Path Finder

Trellis

Hello! I want to create something like this but I want to put them on the same chart and not use the trellis view. My query goes like this:

index="tcpr-dispatcher" host=* sourcetype=DispatcherLogs FinalState=TERMINAL OR FinalState=COMPLETE
|where Module in ("nxtransdirect","proetojt","sep_cid_coversheet") OR (Module in ("previewservice") AND isnotnull(extension))
|timechart count(eval(FinalState="TERMINAL")) as TERMINAL, count(eval(FinalState="COMPLETE")) as COMPLETE span=1month by host

Please help.

Tags (1)
0 Karma

pranaynanda
Path Finder

Is there a way to put them both the bars on a single scale?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...