perhaps the following answer will help you in your task :
Look at this search code which is build with timechart command :
source="airports.csv" |timechart sum(number) as sum by City
The same code search with xyseries command is :
source="airports.csv" |stats sum(number) as sum by _time , City
| eval s1="Aaa" | makemv s1 | mvexpand s1
| eval yval=case(s1=="Aaa",sum)
| eval series=City |convert timeformat="%a %b %d %Y" ctime(_time) AS c_time | xyseries c_time,series,yval
Note that the code : convert timeformat="%a %b %d %Y" ctime(_time) AS c_time is used to change _time command format in the format which is almost like the _time format which appear when we use timechart command.
For more information , click on this link to understand well how use timechart vs xyseries
http://docs.splunk.com/Documentation/Splunk/6.2.0/Search/Chartmultipledataseries
Notice : just replace attentively all my field with your own field .
... View more