Hi All,
i have created a bar chart using stats Count by ID. I have a field "status" in my data. Is it possible to add this status along with ID in the axis of the bar chart. I want my label field to be ID(status). ID and status both are varying data. Is it possible to do in Splunk anyhow?
| eval combined=ID."(".status.")"
| stats count by combined
This is such nice way! The results won't be affected by this calculation right?
Assuming each ID has only one status value, then the results should be the same. It depends on your data.