Hi, I am new to splunk and trying to create a timeline with several individual calculated trend lines, but I simply can not figure out how to. Hopefully someone here is able to help me achieve this.
I have tried the search below which calculates both columns as one total, but i want a total for each eventcode and two separate trend lines
source="*WinEventLog:Security" sourcetype="*wineventlog:security"
EventCode=4624 OR 4625
| timechart count(EventCode) by EventCode
| addtotals row=t
| trendline sma2(Total) as Trend | fields - Total
| rename count(EventCode) as Count
| rename date as date
source="*WinEventLog:Security" sourcetype="*wineventlog:security"
EventCode=4624 OR 4625
|timechart count(EventCode) by EventCode
|untable _time EventCode Count
|trendline sma5(Count) as trends
|eventstats sum(Count) as total by EventCode
Hi ,
Could you try addcoltotals command.
source="*WinEventLog:Security" sourcetype="*wineventlog:security"
EventCode=4624 OR 4625
|timechart count(EventCode) by EventCode
|addcoltotals labelfield="Total"
It might be the solution , but how to I use those two columntotals to create two trend lines?
I can not figure out how to select each columntotal for use in trendline