I want to create a chart showing the attendance between pre covid (February) and current covid (July) for one of our offices. This is my current search which gets me the data I need but I'm unsure on how to overlap the data so we can see the direct comparison.
| multisearch
[search index="physec_app_lenel" EVDESCR="Access Granted" READERDESC="TOK*" earliest="07/01/2020:20:00:00" latest="07/28/2020:23:00:00"
| eval Attendance="July"]
[search index="physec_app_lenel" EVDESCR="Access Granted" READERDESC="TOK*" earliest="02/01/2020:01:00:00" latest="02/28/2020:23:00:00"
| eval Attendance="February"]
| timechart span=1w dc(CARDNUM) by Attendance
All you need to do is adjust the time range of one of the searches so it lines up with the other search.
| multisearch
[search index="physec_app_lenel" EVDESCR="Access Granted" READERDESC="TOK*" earliest="07/01/2020:20:00:00" latest="07/28/2020:23:00:00"
| eval Attendance="July"]
[search index="physec_app_lenel" EVDESCR="Access Granted" READERDESC="TOK*" earliest="02/01/2020:01:00:00" latest="02/28/2020:23:00:00"
| eval Attendance="February"
| eval _time=_time + strptime("07/01/2020:20:00:00", "%m/%d/%Y:%H:%M:%S") - strptime("02/01/2020:20:00:00", "%m/%d/%Y:%H:%M:%S")]
| timechart span=1w dc(CARDNUM) by Attendance
Hey thanks for the reply! I tried doing this but it seems to connect both series into one when I try
I got it to work thank you so much for your help!