Splunk Enterprise Security

How do I display 2 lines on a line graph? The fields used are "MatlTemp" and "Hour" and it is sorted by "Batch"

donny__0
Engager

I am using 2 csv files and the "inputlookup" method.  Right now I am appending one of the csv to another csv, but the line chart that is displayed out only have one line. Both of the csv files has the same fields but i want the the graph to have 2 lines, one line for the first "batch" and the second line for the second "Batch" . How do I write the codes to let the graph get sorted by the "Batch" number so there will be 2 lines?

Current codes : 

 | from inputlookup:"5019609_V-094_9007270566.csv"| append [| from inputlookup "5019609_V-094_9007280926.csv"] |  fields  Hr  MatlTemp

Current Picture of line graph :

donny__0_1-1615533293110.png

 

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
You could rename one of those MatlTemp eg. MatlTemp2 inside append and add also that field to the end of fields.

donny__0
Engager

Okay a second line appeared but is it there a solution to sort the line chart by fields instead? I have a big data so its not efficient to rename the fields every time I want to compare a new set of data. If there is a sorting solution then the data would automatically be sorted by the "Batch" number. Thank You!

 

 

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...