Splunk Search

Two timecharts for different time frames (today/yesterday) on one graph

dab55
Engager

Hi all,

I'm trying to create a chart containing two timecharts for different time frames (e.g. today/yesterday). How can I achieve it?
Currently I'm getting it one after another on the same graph. I'd like basically to overlay one timechart on another one.
 
index=ddos device_event_class_id=Bandwidth earliest=-1d@d latest=-0d@d | rex field=msg "msg=.+raffic.+'(?<pg_name>[\w\s\-]+)'.+(?<bps>\d+\.\d+\s.+)\..+" | eval ReportKey="yersterday" | timechart span=3h count by pg_name | append [search index=ddos device_event_class_id=Bandwidth earliest=-2d@d latest=-1d@d | rex field=msg "msg=.+raffic.+'(?<pg_name>[\w\s\-]+)'.+(?<bps>\d+\.\d+\s.+)\..+" | eval ReportKey="beforeyesterday" | timechart span=3h count by pg_name ] | fillnull value=0 | eval mytime=strftime(_time, "%H:%M") | sort mytime

2021-04-15_13-19-23.png

 

Thanks in advance.

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Try adding:

| timewrap d

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Try adding:

| timewrap d

dab55
Engager

@ITWhisperer @richgalloway 

Thanks a lot!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check out the timewrap command.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...