Getting Data In

Display timechart "BY" multiple lines in one chart

royimad
Builder

I have a search with a timechart grouped by a fieldname that would like to displayed on a multilines chart on the same graph, How i can do that?

host="fieldcontroller.wavemark.net" sourcetype="zenosseventhistory" 
| where MESSAGE like "%Low Power%" 
| rex field=MESSAGE "Power :(?<Voltage>.{5})" 
| timechart span=1d eval(min(LowVolt)) as LowVoltage by DEVICE
Tags (2)
0 Karma
1 Solution

lguinn2
Legend

I am not sure why you need the eval. Does the following work?

host="fieldcontroller.wavemark.net" sourcetype="zenosseventhistory" 
| where MESSAGE like "%Low Power%" 
| rex field=MESSAGE "Power :(?<Voltage>.{5})" 
| timechart span=1d min(LowVolt) as LowVoltage by DEVICE

View solution in original post

lguinn2
Legend

I am not sure why you need the eval. Does the following work?

host="fieldcontroller.wavemark.net" sourcetype="zenosseventhistory" 
| where MESSAGE like "%Low Power%" 
| rex field=MESSAGE "Power :(?<Voltage>.{5})" 
| timechart span=1d min(LowVolt) as LowVoltage by DEVICE
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...