I have the following two queries -
index=_internal connection | timechart count by splunk_server
index=_internal cooked connection | timechart count by splunk_server
How can I overlay them?
Depending on what i was trying to achieve, I'd tend to do something like this.
| eval cooked=case(match(_raw,"cooked"),1)
| timechart count as total sum(cooked) as cooked by splunk_server
View solution in original post