Splunk Search

timechart for post for multiple web sites

riqbal47010
Path Finder

I have multiple web portals.

portal= www.xyz.com, www.abc.com
post_method = get | post

Now I want a timechart like values(post_method) by portal
then I want to use trellis option like for each portal there is seperate graph with number of get and post requests.

0 Karma
1 Solution

woodcock
Esteemed Legend

Like this:

index="YouShouldAlwaysSpecifyAnIdex" AND sourcetype="AndSourcetypeToo" AND portal IN("www.xyz.com", "www.abc.com")
| timechart count(eval(post_method=="get")) AS Gets count(eval(post_method=="post")) AS Posts BY portal

Then the trellis function be functional and you can just click on which split you like ( portal or post_method )

View solution in original post

0 Karma

woodcock
Esteemed Legend

Like this:

index="YouShouldAlwaysSpecifyAnIdex" AND sourcetype="AndSourcetypeToo" AND portal IN("www.xyz.com", "www.abc.com")
| timechart count(eval(post_method=="get")) AS Gets count(eval(post_method=="post")) AS Posts BY portal

Then the trellis function be functional and you can just click on which split you like ( portal or post_method )

0 Karma

riqbal47010
Path Finder

thanks

it is working now as expected.

Sukisen1981
Champion

you cant timechart strings, what you need is timechart acount of get or post..something like |timechart count by post_method. You of course can not have 2 fields in the by clause.suggest using stats instead something like
|bin span=1h _time|stats count by post_method,portal

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...