Now I have two fields(named field 1 and field 2) for one log file. Field 2 just has two kinds of value "1" and "2". I want to build a chart to show field 1's value when field 2's value equals "1". How can I do that? Thanks for any help!
One way...
... | where field2=1 | table field1
eh...quite easy...I'm not familiar with Splunk search language...Thank u
Or just: source=mylog field2=1 | ...