Will Splunk do a stacked area chart? I'm able to get an area chart, but it's not 'stacked' (so each proxy totals to an aggregate). I'm wondering if splunk can even do that? I looked at the documentation and it appeared that it could, so I'm hoping maybe I'm just doing something wrong. Under the 'Visualization"
index = "myindex"| bin _time span=5m
| stats sum(cs_bytes) as Bytes by proxy_server _time
| eval Kbps=(((Bytes*8)/1000)/300)
| timechart span=5m list(Kbps) by proxy_server