Hello,
I have a timechart with multiple fields, I want to append existing query or add new query to display one field as a text in graph.
Example:
I am having above graph, want to display text (field) from search query at the two purple circles .
Thanks,
Hello @smahuja ,
Not sure what you exactly mean.
If the filename/objectname is in the results of your annotation search, you can display it as the text of the Annotation.
| eval annotation_label = <field>
Is that what you need?
Hi @smahuja ,
Should the text also be alligned to some time on the chart?
If I understood your request correct, you could work with Event Annotation.
https://docs.splunk.com/Documentation/Splunk/latest/Viz/ChartEventAnnotations
You have to edit the Dashboards XML as described in the Documentation.
Hope this helps.
Ralph
Hello @smahuja ,
Not sure what you exactly mean.
If the filename/objectname is in the results of your annotation search, you can display it as the text of the Annotation.
| eval annotation_label = <field>
Is that what you need?