Hello, I'm starting out on my splunk journey and have been tasked with figuring out a dashboard for my executives. I created a layout for a dashboard and had the idea of creating a chart, but have been struggling with the logic. What I'm looking to do is have a the count/average count over time by time so I have a chart of percentages of the day against their average thruput. I had a few ideas for the search but none seemed to work. could someone give me some direction please on what I've gotten so far? (its definitely wrong) index=* | where index="Index 1" OR index="Index 2" OR index="Index 3" | eval Count=sum(count(index)) / "something something something to get the average" | timechartcount by Count
... View more