I want to show an area graph with an average line trough it.
This is the search I'm using:
eventtype=windows_performance object=Process | timechart span=5m count as Alerts | appendcols [search eventtype=windows_performance object=Process | stats count as average | eval average=average/48] | eventstats first(average) as test | fields - average
What is does it create a timechart for the last 4 hours, then I search for the total number and divide it to match the timechart span (4hours = 240minutes, 240m/5m = 48)
This graph is almost showing what I want, but for the second series I want a line, not area.
You might go install/look at the Splunk 6 Dashboard Examples app. In there, you'll find a working D3 example which is included with 6 that's pretty slick of a custom chart overlay which should help. Perhaps you can use that as is, or modify to suit.