Splunk Search

Is it possible to use two independent/unrelated queries in a timechart?

jbrenner
Path Finder

I have two independent/unrelated queries (same index, though) , and I want to create a timechart where there are two bars in each time bucket, one for each of the two queries. Is this possible?

Thanks!

Jonathan

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Yes or perhaps no - it depends on your queries

Essentially, each bar on the chart represents a series, so your search should deliver two series, one for each query.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...