sourcetype="A" category="CatA" "msg string in my log not stored as a field" | timechart span=1h count(_raw)
this gives me a single charted line which tracks occurrences of that particular log with string specified. I hav several of such lines. However is there a way to save each of this 'search' under a single name so that i can combine them into a single chart?
im not sure if this is possible (i suspect it has to do with eval)? any tips?
Event looks like this:
6/27/2011 3:47:02 AM 6/27/2011 3:47:02 AM pss2wlsfe2b [ps2wseb] PS.RR.SV.APP Full GC detected in log file [directory/gc.log] line  (5 occurrences since 11:42:01) CLOSED WARNING App
so basically, from "Full GC detected in log file [directory/gc.log] line 254988"
they are replacable by the following messages as well.