Splunk Search

How to chart multiple field values on the y-axis with a single value on the x-axis?


I have hosts with multiple sql id and elapsed time. I have to chart, per host, sql ids against elapsed time. Can anyone help?

Tags (2)
0 Karma


Try chart command on a stacked chart

.... | chart avg(elapsed_time) as elapsed_time over host by sql_id
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!