Hi Everyone,
I am trying to combine the outputs of two different searches one chart. Presently, I have the Disk Reads/sec and Disk Writes/sec on different charts, but I want the data representation to appear together on the same chart. How can I do this?
SPL below:
index=perfmon counter="Disk Reads/sec" OR counter="Disk Writes/sec Host="*" collection=LogicalDisk [search index=perfmon counter="Disk Reads/sec" Host=megatron collection=PhysicalDisk | stats avg(Value) as Disk__sec_read by host | fields host ] | eval dataValue="latency:" + tostring(round(latency,3)) + "," + "Disk Reads:" + tostring(round(Value,3)) | makemv delim="," allowempty=true dataValue | mvexpand dataValue | eval part=split(dataValue,":") | eval category = Host + ":" + mvindex(part,0) | eval dataPoint = tonumber(mvindex(part,1)) | timechart span=5m latest(dataPoint) by category
http://answers.splunk.com/storage/temp/59228-combine.jpg
... View more