Splunk Enterprise

help on append command in a line chart

jip31
Motivator

hello

I need to display 2 curves in my line chart from two different index

so i am doing this :

index="disk" sourcetype="Perfmon:disk" 
| bin span=10m _time 
| eval time=strftime(_time, "%H:%M:%S") 
| stats avg(Value) as Disque by time 
| eval Disque=round(Disque, 2) 
| append
    [ search index="mem" sourcetype="Perfmon:mem" 
    | bin span=10m _time 
    | eval time=strftime(_time, "%H:%M:%S") 
    | stats avg(Value) as Mémoire by time 
    | eval Mémoire=round(Mémoire, 2)]

the problem I have is that on the x axis my curves are not aligned on the same time slot

jip31_0-1707207151990.png

what is wrong please?

thanks

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

You need to get  your stats into the same events. Try something like this

index="disk" sourcetype="Perfmon:disk" 
| bin span=10m _time 
| eval time=strftime(_time, "%H:%M:%S") 
| rename Value as Disque 
| append
    [ search index="mem" sourcetype="Perfmon:mem" 
    | bin span=10m _time 
    | eval time=strftime(_time, "%H:%M:%S") 
    | rename Value as Mémoire]
| stats avg(Disque) as Disque avg(Mémoire) as Mémoire by time 
| eval Disque=round(Disque, 2) 
| eval Mémoire=round(Mémoire, 2)

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You need to get  your stats into the same events. Try something like this

index="disk" sourcetype="Perfmon:disk" 
| bin span=10m _time 
| eval time=strftime(_time, "%H:%M:%S") 
| rename Value as Disque 
| append
    [ search index="mem" sourcetype="Perfmon:mem" 
    | bin span=10m _time 
    | eval time=strftime(_time, "%H:%M:%S") 
    | rename Value as Mémoire]
| stats avg(Disque) as Disque avg(Mémoire) as Mémoire by time 
| eval Disque=round(Disque, 2) 
| eval Mémoire=round(Mémoire, 2)
0 Karma

jip31
Motivator

thanks

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...