Dashboards & Visualizations

How do you build a chart with multiple searches from multiple indexs over time?

khhenderson
Path Finder

We are trying to build a chart to show the amount of connection errors and successful connections in a time chart by count.

The data is in 2 indexes.

There are 3 searches.

1.

index=index1 IllegalMonitorStateException CurrentUrl=‘name.domain.com/path/to/endpoint' | chart count as IllegalMonitorStateException

2.

index=index1 host=“appserver-prod*” source="*activity.log" activity="user.login*"  activity="user.login.ldap" accountGuid=00000000-0000-1234-5678-000000000000 | chart count by accountGuid

3.

host=“loadbalance-prod*” index=index2 uri_path=/path/to/endpoint method=POST referer="https://name.domain.com/*" | stats count by status, host
0 Karma

woodcock
Esteemed Legend

Show us the results of each search and the show us a mockup of what you would like the combination output to be. You have not given us enough detail to help you.

0 Karma

khhenderson
Path Finder

ok, I'll put it up when I have a moment

0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

hi @khhenderson,

Did you end up solving this problem?

0 Karma

khhenderson
Path Finder

@mstjohn_splunk No, haven't had a chance to get back to it... but thanks for the follow up.

0 Karma
Get Updates on the Splunk Community!

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...