Splunk Search

How do you overlay charts that are linked together with a field?

splunkuser2127
Loves-to-Learn

I have 3 extraction fields: "guid", "runtime_general", "runtime_specific".

There is also a value "A" that I will search to get the values I need.
I want to overlay runtime_general and runtime_specific (y-axis) and have the x-axis be guid.

I have two pertinent log types:
1) "A: guid, runtime_general" where A is always the same (as I'm searching on A)
2) "guid, runtime_specific"

How do I chart all the guids I get by searching for value A, and overlay it with both runtimes? I'm very unfamiliar with Splunk so any help would be appreciated.

0 Karma
Get Updates on the Splunk Community!

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...

From Alert to Resolution: How Splunk Observability Helps SREs Navigate Critical ...

It's 3:17 AM, and your phone buzzes with an urgent alert. Wire transfer processing times have spiked, and ...