Splunk Search

Is it possible to use two independent/unrelated queries in a timechart?

jbrenner
Path Finder

I have two independent/unrelated queries (same index, though) , and I want to create a timechart where there are two bars in each time bucket, one for each of the two queries. Is this possible?

Thanks!

Jonathan

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Yes or perhaps no - it depends on your queries

Essentially, each bar on the chart represents a series, so your search should deliver two series, one for each query.

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...