Splunk Search

Can a result of one query can be used in multiple timechart ?

pradjswl
Explorer

I can use a query that display the result in verbose mode with all fields displayed in interesting field area. I would like to create a timechart of all of those specif fields. Those fields are not at all related with each other(example: Market, submarket, ErrCode, ErrDescription, Exception etc). I can create a timechart of one field at a time(Query | timechart span=1d count by fieldname). Is there a way to create a multiple different timechart using the query only once ?

Thanks in Advance for your valuable suggestion.

Tags (1)
0 Karma
1 Solution

renjith_nair
Legend

You can use your main search as base search and use the same search results in multiple panels in a dashboard using post process.

Reference : http://docs.splunk.com/Documentation/Splunk/6.4.2/Viz/Savedsearches#Post-process_searches

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

renjith_nair
Legend

You can use your main search as base search and use the same search results in multiple panels in a dashboard using post process.

Reference : http://docs.splunk.com/Documentation/Splunk/6.4.2/Viz/Savedsearches#Post-process_searches

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

pradjswl
Explorer

Thank you so much @renjith.nair

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...