Splunk Search

Merge two line chart with different query in to single line chart

karthi25
Path Finder

I have two line chart with different queries as follows:

 <chart>
            <search>
              <query>index=*** source=*** |spath path=TestSplunkLog.TestFailureLog.payload.failureCount output=failureCount|spath path=TestSplunkLog.TestFailureLog.payload.startTime output=startDate| sort -splunkLogId | eval runDate = strftime(strptime(startDate, "%Y-%m-%d %H:%M"),"%Y-%m-%d %H:%M") | chart  values(failureCount) as FAILURERECORDCOUNT over runDate</query>
              <earliest>$dashboardTime.earliest$</earliest>
              <latest>$dashboardTime.latest$</latest>
              <refresh>30m</refresh>
              <refreshType>delay</refreshType>
            </search>
            <option name="charting.axisTitleX.text">Date</option>
            <option name="charting.axisTitleY.text">Record Count</option>
            <option name="charting.axisY.scale">linear</option>
            <option name="charting.chart">line</option>
            <option name="charting.chart.showDataLabels">none</option>
            <option name="charting.legend.placement">none</option>
          </chart>

    <chart>
            <search>
              <query>index=*** source=*** |spath path=TestSplunkLog.TestSuccessLog.payload.successCount output=successCount|spath path=TestSplunkLog.TestSuccessLog.payload.startTime output=startDate| sort -splunkLogId | eval runDate = strftime(strptime(startDate, "%Y-%m-%d %H:%M"),"%Y-%m-%d %H:%M") | chart  values(successCount) as SUCCESSRECORDCOUNT over runDate</query>
              <earliest>$dashboardTime.earliest$</earliest>
              <latest>$dashboardTime.latest$</latest>
              <refresh>30m</refresh>
              <refreshType>delay</refreshType>
            </search>
            <option name="charting.axisTitleX.text">Date</option>
            <option name="charting.axisTitleY.text">Record Count</option>
            <option name="charting.axisY.scale">linear</option>
            <option name="charting.chart">line</option>
            <option name="charting.chart.showDataLabels">none</option>
            <option name="charting.legend.placement">none</option>
          </chart>

Now, I want to merge this two line chart and convert it to single multi-line chart. Since the JSON path varies, I felt difficult to do this. Can anyone please help me on this.

0 Karma

woodcock
Esteemed Legend

Can you work with this?

index=*** source=*** |spath path=TestSplunkLog.TestSuccessLog.payload ...
0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...