Dashboards & Visualizations

How do you build a chart with multiple searches from multiple indexs over time?

khhenderson
Path Finder

We are trying to build a chart to show the amount of connection errors and successful connections in a time chart by count.

The data is in 2 indexes.

There are 3 searches.

1.

index=index1 IllegalMonitorStateException CurrentUrl=‘name.domain.com/path/to/endpoint' | chart count as IllegalMonitorStateException

2.

index=index1 host=“appserver-prod*” source="*activity.log" activity="user.login*"  activity="user.login.ldap" accountGuid=00000000-0000-1234-5678-000000000000 | chart count by accountGuid

3.

host=“loadbalance-prod*” index=index2 uri_path=/path/to/endpoint method=POST referer="https://name.domain.com/*" | stats count by status, host
0 Karma

woodcock
Esteemed Legend

Show us the results of each search and the show us a mockup of what you would like the combination output to be. You have not given us enough detail to help you.

0 Karma

khhenderson
Path Finder

ok, I'll put it up when I have a moment

0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

hi @khhenderson,

Did you end up solving this problem?

0 Karma

khhenderson
Path Finder

@mstjohn_splunk No, haven't had a chance to get back to it... but thanks for the follow up.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...