Dashboards & Visualizations

Timechart Count by Field Name... By Field Name (Combining Timecharts)

PaintItParker
Explorer

I have two timecharts:

 

index=my_index sourcetype=my_sourcetype
| where area="area1"
| regex message="(?:(^Problem.*)|((?i).*Issue.*)|((?i).*Error.*))"
| timechart count by message

 

and

 

index=my_index sourcetype=my_sourcetype
| where area="area2"
| regex message="(?:(^Problem.*)|((?i).*Issue.*)|((?i).*Error.*))"
| timechart count by message

 

The only thing that makes them different is that one is looking at logs where the value of area is area1, and the other is looking at area2.

Rather than have two separate timecharts, I would like to have one timechart with a line for area1 and a line for area2, looking at the count of Issues for each over the given period of time. I do not need a span because the dashboard implements that for me with the time range selection feature.

How could I go about this? I tried something like "timechart count by message by area"  but that does not work. Thank you.

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Have you tried something like this:

index=my_index sourcetype=my_sourcetype (area="area1" OR area="area2")
| regex message="(?:(^Problem.*)|((?i).*Issue.*)|((?i).*Error.*))"
| timechart count by message area

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Have you tried something like this:

index=my_index sourcetype=my_sourcetype (area="area1" OR area="area2")
| regex message="(?:(^Problem.*)|((?i).*Issue.*)|((?i).*Error.*))"
| timechart count by message area
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...