Splunk Search

How do I put a line graph that shows data in both indexes into one graph?

WXY
Path Finder

Hi,

I want to get a line graph with two indexes of data.

My command is index=interface sourcetype="in_t"| timechart count and index=imp sourcetype="out_t"| timechart count

What should I do?

Tags (2)
0 Karma
1 Solution

renjith_nair
Legend

@WXY,

Try

(index=interface OR index=imp) (sourcetype="in_t" OR sourcetype="out_t")|timechart count by sourcetype
---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi WXY
try

(index=interface sourcetype="in_t") OR (index=imp sourcetype="out_t")
| timechart count

Bye.
Giuseppe

0 Karma

renjith_nair
Legend

@WXY,

Try

(index=interface OR index=imp) (sourcetype="in_t" OR sourcetype="out_t")|timechart count by sourcetype
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...