Dashboards & Visualizations

How can I overlay one chart on top of the other?

danielbb
Motivator

I have the following two queries -

index=_internal connection  | timechart count by splunk_server

index=_internal cooked connection  | timechart count by splunk_server

How can I overlay them?

0 Karma
1 Solution

DalJeanis
Legend

Depending on what i was trying to achieve, I'd tend to do something like this.

 index=_internal connection 
 | eval cooked=case(match(_raw,"cooked"),1)
| timechart count as total sum(cooked) as cooked by splunk_server

View solution in original post

DalJeanis
Legend

Depending on what i was trying to achieve, I'd tend to do something like this.

 index=_internal connection 
 | eval cooked=case(match(_raw,"cooked"),1)
| timechart count as total sum(cooked) as cooked by splunk_server
Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...