Hello All,
I have some data coming in from NetApp that shows snapshot name and snapshot volume used. I need to show all the volume names/space used from 48 hours ago on-top of one from 24 hours ago. The goal is to show growth of our snapshots each day.
by base search is :
sourcetype=dbx3_netapp_vault_utilization
this will return the below data: (server/host names redacted)
I need the chart to show the name with Volume Used at 24h and 48 on the same line graph...any help?
Assuming that your "Volume Used (GB)" is extracted as a field, you should be able to plot that day by day comparison using timechart-timewrap command combination.
https://docs.splunk.com/Documentation/Splunk/7.1.2/SearchReference/Timewrap