I have a search that returns time as this:
Apr 25 2014 14:51:40 GMT: INFO (nsup): (base/thr_nsup.c:1249) {ddp-ns} Records: 17798730, 17798730 0-vt, 0(0) expired, 0(0) evicted, 0(0) set deletes, 0(0) set evicted. Evict ttls: 0,0,0.000. Waits: 0,0,0. Total time: 3169 ms
I would like to chart this total time over time but not having luck. thanks.
I got it going thanks.
If possible, add the answer that you arrived to here and accept/close the answer.
This one event that you're indexing in splunk or output of a search? You could extract Total time in a field and do a timechart.