Splunk Search

How can i make my chart overlay use the same axis?

tarini_r
New Member

I have my search query being as such where I am displaying the tickets, flowing in and out. Now, i want to put a line indicating the backlog on my chart.

index="tickets" $year$  |  dedup number 
| convert timeformat="%Y-%m-%d %H:%M:%S" num(allFields.createdDate) As days
| eval week=strftime(days,"%V") 
| eval year = strftime(days, "%Y") 
| where year= c_year
| stats count by week

| appendcols [search index="tickets" $year$ | dedup number | search state != "Resolved" AND state != "Closed" AND state != "Resolution Confirmed" AND  assignment_group != "Out of Scope" | convert timeformat="%Y-%m-%d %H:%M:%S" num(createdDate) As date
| eval weeks=strftime(date,"%V") 
| eval year = strftime(date, "%Y") 
| where year= c_year | chart count by weeks 
 ]


| appendcols [search index="tickets" $year$  | dedup number
| search state = "Resolved" OR state = "Resolution Confirmed" OR  state = "Closed"
| convert timeformat="%Y-%m-%d %H:%M:%S" num(resolvedOn) As days
| eval out = strftime(days, "%V")
| eval year = strftime(days, "%Y") 
| where year= c_year
| chart count by out]

Basically, how can i make the field 'createdDate' used in first query and first subquery to be common on my chart? The way i did it, the subquery has its own axis, which i do not want. Please refer to the picture:alt text
What I am getting is this : (where weeks is my backlog)
alt text
Any help will be much appreciated!

Labels (4)
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...