Splunk Search

How do you overlay charts that are linked together with a field?

splunkuser2127
New Member

I have 3 extraction fields: "guid", "runtime_general", "runtime_specific".

There is also a value "A" that I will search to get the values I need.
I want to overlay runtime_general and runtime_specific (y-axis) and have the x-axis be guid.

I have two pertinent log types:
1) "A: guid, runtime_general" where A is always the same (as I'm searching on A)
2) "guid, runtime_specific"

How do I chart all the guids I get by searching for value A, and overlay it with both runtimes? I'm very unfamiliar with Splunk so any help would be appreciated.

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!