Dashboards & Visualizations

How do you build a chart with multiple searches from multiple indexs over time?

khhenderson
Path Finder

We are trying to build a chart to show the amount of connection errors and successful connections in a time chart by count.

The data is in 2 indexes.

There are 3 searches.

1.

index=index1 IllegalMonitorStateException CurrentUrl=‘name.domain.com/path/to/endpoint' | chart count as IllegalMonitorStateException

2.

index=index1 host=“appserver-prod*” source="*activity.log" activity="user.login*"  activity="user.login.ldap" accountGuid=00000000-0000-1234-5678-000000000000 | chart count by accountGuid

3.

host=“loadbalance-prod*” index=index2 uri_path=/path/to/endpoint method=POST referer="https://name.domain.com/*" | stats count by status, host
0 Karma

woodcock
Esteemed Legend

Show us the results of each search and the show us a mockup of what you would like the combination output to be. You have not given us enough detail to help you.

0 Karma

khhenderson
Path Finder

ok, I'll put it up when I have a moment

0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

hi @khhenderson,

Did you end up solving this problem?

0 Karma

khhenderson
Path Finder

@mstjohn_splunk No, haven't had a chance to get back to it... but thanks for the follow up.

0 Karma
Get Updates on the Splunk Community!

Is there an add-on for the Cisco Meraki devices?

We have many Cisco Meraki devices sending data via syslog to Splunk. Is there an add-on for ...

How to create a WIDS/IDPS/Internet Content Filtering dashboard in Splunk?

I need help on how to create a WIDS/IDPS/Internet Content Filtering dashboard in Splunk so that I can ...

Events has wrong timestamp, How to correct time config?

Hello Splunkers, I've an issue with my event time configuration. It has incorrect timestamp. Below are my ...