Can Splunk show (and if so, how?) different scales for each line in a line graph while auto-computing the correct scale for each (meaning the lines will auto-size their height based on the max value for each metric)?
more details: in a security-related view, I'd like to chart attempted logins/day and failed logins/day on the same line graph. But attempted logins will (hopefully!) outnumber failed logins by 100x or more. So I'd like to use different scales for each metric.
@sxp5686, You're asking a new question in a thread that is more than 7 years old. For better chances at getting help, please post a new question.
I found that you can do this, at least in v6.1.
In the visualization editor...
That should do it.
I am at a client that is requesting this functionality as well. They want to be able to plot the number of sessions opened (in the thousands) and the percentage of memory used on the same graph to show correlation.
Is this possible?
looking at the other answers, it looks like (so far at least) no one has figured out how to do this.
Have you tried applying a log scale to the graph? Seems like a good use case for graphing counts that are in the 10x or 100x difference.
I was hopeful that the Multiseries 'split' chart type would do this, but each of the series adhere to the same scale.
I also think this could be good seperated into two stacked graphs measuring the same time period. You would need to make a view that incorporated separate searches into it.
If you are more interested in relative trends than actual counts you could try normalizing the data. It might be as simple as "| timechart loginCount/max(loginCount) failedCount/max(failedCount)"
That would give you a peak value of "1" for both (when you are the max for your search interval).
Multiple scale graphs are generally considered poor visualizations and should be avoided.