Splunk Search

Two timecharts for different time frames (today/yesterday) on one graph

dab55
Engager

Hi all,

I'm trying to create a chart containing two timecharts for different time frames (e.g. today/yesterday). How can I achieve it?
Currently I'm getting it one after another on the same graph. I'd like basically to overlay one timechart on another one.
 
index=ddos device_event_class_id=Bandwidth earliest=-1d@d latest=-0d@d | rex field=msg "msg=.+raffic.+'(?<pg_name>[\w\s\-]+)'.+(?<bps>\d+\.\d+\s.+)\..+" | eval ReportKey="yersterday" | timechart span=3h count by pg_name | append [search index=ddos device_event_class_id=Bandwidth earliest=-2d@d latest=-1d@d | rex field=msg "msg=.+raffic.+'(?<pg_name>[\w\s\-]+)'.+(?<bps>\d+\.\d+\s.+)\..+" | eval ReportKey="beforeyesterday" | timechart span=3h count by pg_name ] | fillnull value=0 | eval mytime=strftime(_time, "%H:%M") | sort mytime

2021-04-15_13-19-23.png

 

Thanks in advance.

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Try adding:

| timewrap d

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Try adding:

| timewrap d

dab55
Engager

@ITWhisperer @richgalloway 

Thanks a lot!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check out the timewrap command.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...