Splunk Search

Is it possible to use two independent/unrelated queries in a timechart?

jbrenner
Path Finder

I have two independent/unrelated queries (same index, though) , and I want to create a timechart where there are two bars in each time bucket, one for each of the two queries. Is this possible?

Thanks!

Jonathan

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Yes or perhaps no - it depends on your queries

Essentially, each bar on the chart represents a series, so your search should deliver two series, one for each query.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...