Splunk Search

Two intention searches on one timechart

lain179
Communicator

Hi,

I have two separate searches that I would like to put together one graph. I don't think I can use a join because they are both intention searches. I think I can't use chart overlay either.

The usage is that the user will choose a server from a drop down list, which will trigger those two searches separately. One search creates an area timechart and the second one creates a splitSeries line timechart. Now I have them on two separate chart but I would like to put them on one time chart if possible.

Appreciate any help.

Thanks.

Tags (2)
0 Karma

jonuwz
Influencer

Its possible but not easy.

You're going to need to come up with a search that mashes all the data into a a single result

i.e.

_time  area_value  split_value1 split_value2 split_value3

Then play with multi axis graphs.
Example here - the color stuff can be ignored - I needed that or something else.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...