Splunk Enterprise

help on append command in a line chart

jip31
Motivator

hello

I need to display 2 curves in my line chart from two different index

so i am doing this :

index="disk" sourcetype="Perfmon:disk" 
| bin span=10m _time 
| eval time=strftime(_time, "%H:%M:%S") 
| stats avg(Value) as Disque by time 
| eval Disque=round(Disque, 2) 
| append
    [ search index="mem" sourcetype="Perfmon:mem" 
    | bin span=10m _time 
    | eval time=strftime(_time, "%H:%M:%S") 
    | stats avg(Value) as Mémoire by time 
    | eval Mémoire=round(Mémoire, 2)]

the problem I have is that on the x axis my curves are not aligned on the same time slot

jip31_0-1707207151990.png

what is wrong please?

thanks

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

You need to get  your stats into the same events. Try something like this

index="disk" sourcetype="Perfmon:disk" 
| bin span=10m _time 
| eval time=strftime(_time, "%H:%M:%S") 
| rename Value as Disque 
| append
    [ search index="mem" sourcetype="Perfmon:mem" 
    | bin span=10m _time 
    | eval time=strftime(_time, "%H:%M:%S") 
    | rename Value as Mémoire]
| stats avg(Disque) as Disque avg(Mémoire) as Mémoire by time 
| eval Disque=round(Disque, 2) 
| eval Mémoire=round(Mémoire, 2)

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You need to get  your stats into the same events. Try something like this

index="disk" sourcetype="Perfmon:disk" 
| bin span=10m _time 
| eval time=strftime(_time, "%H:%M:%S") 
| rename Value as Disque 
| append
    [ search index="mem" sourcetype="Perfmon:mem" 
    | bin span=10m _time 
    | eval time=strftime(_time, "%H:%M:%S") 
    | rename Value as Mémoire]
| stats avg(Disque) as Disque avg(Mémoire) as Mémoire by time 
| eval Disque=round(Disque, 2) 
| eval Mémoire=round(Mémoire, 2)
0 Karma

jip31
Motivator

thanks

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...