I have a query to search and display events in a timechart by severity. And on the chart i would like to display a linear trendline for events with (say) critical severity. How can i achieve this?
You could try using appendcols : https://docs.splunk.com/Documentation/Splunk/7.1.0/SearchReference/Appendcols
If you provide your specific query it might help to get more specific.