I have 3 extraction fields: "guid", "runtime_general", "runtime_specific".
"guid", "runtime_general", "runtime_specific"
There is also a value "A" that I will search to get the values I need.
I want to overlay runtime_general and runtime_specific (y-axis) and have the x-axis be guid.
I have two pertinent log types:
1) "A: guid, runtime_general" where A is always the same (as I'm searching on A)
2) "guid, runtime_specific"
"A: guid, runtime_general"
How do I chart all the guids I get by searching for value A, and overlay it with both runtimes? I'm very unfamiliar with Splunk so any help would be appreciated.