run the below query and got the output
index=xxx sc_status=201 OR sc_status=200
| stats count(eval(sc_status)) as "Total Hits", avg(time_taken) as Avg_Time_Taken by date, cs_host, sc_status
Concern:
required different Color based on status on y-axis(Total value)
Required Out as per the below screen shot.
)
Splunk column chart cannot be displayed with two values on x-axis.
This is not possible because the chart is trying to separate the time and host values.