Hi all,
I have loaded the last 3 years of historical data from a CSV file to Splunk — so source is "XYZ.csv". On the other hand, the recent log data is tracking every 30 mins through a REST API — thus its source is ""rest://XYZ".
Can you please advise how I can plot a timechart with both data sets together?
Do both log sources (CSV and REST API) have the same log format, i.e. do they have the same fields available?
If so, I suggest you run two searches to combine all events and then run the timechart command:
index=... sourcetype="XYZ.csv"
| append [search index=... sourcetype="rest://XYZ"]
| timechart ...
EDIT: I just thought of something much simpler:
index=... sourcetype="XYZ.csv" OR sourcetype="rest://XYZ"
Do both log sources (CSV and REST API) have the same log format, i.e. do they have the same fields available?
If so, I suggest you run two searches to combine all events and then run the timechart command:
index=... sourcetype="XYZ.csv"
| append [search index=... sourcetype="rest://XYZ"]
| timechart ...
EDIT: I just thought of something much simpler:
index=... sourcetype="XYZ.csv" OR sourcetype="rest://XYZ"
I just edited my answer to include a much simpler search using "OR".