Splunk Search
Highlighted

How do you overlay two time charts?

Communicator

I have two timecharts that I'd like to overlay them on one chart

example search to produce the two charts

source=a | timechart count by host

source=b | timechart count by host

I was hoping I could do

`source=a | eventstats count as a by host | search source=b  eventstats count as b by host | timechart avg(a), avg(b) by host`

Is this possible?

0 Karma
Highlighted

Re: How do you overlay two time charts?

Splunk Employee
Splunk Employee

are you looking for?

source=a OR source=b | timechart count by host, source 
Highlighted

Re: How do you overlay two time charts?

Communicator

Perhaps my example was too simplistic. Let's stay the one data set is avg CPU and the second Memory usage

0 Karma