Splunk Search

Timechart of two stats with split by same field, one as overlay, then color code columns based on uncharted value


I've been doing ugly hacks around this need for months and now I need to dig in and figure out an eloquent solution even if it means learning some new skills. I need to | timechart two stats - Total Turnin Time and Files changed per Turnin, split by the same FileID. I'd like the Files changed per Turnin value to be an overlay as below. I can achieve this below by manually selecting the overlay fields for each concatenation of Files Changed per Turnin:FileID, but this won't transfer to a dashboard where FileID is filled by token. Is there a way to use a wildcard in the overlay field?

It's important to know that from here the FileID is being passed through drill down. I was working on a concatenation of the FileID and value of Files Changed per Turnin so that it would be displayed in the tooltip, but then I couldn't pass the FileID.

Finally, I'd like to color-code the columns based on yet another filed value, TurninStatus. You can see below that this search is only for TurninStatus=P. I currently have an entirely separate view for TurninStatus=F.

Thanks very much for any thoughts or suggestions on any part of the issue.

alt text

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...