Hi
I want to overlay two different time charts in one panel.
can this be done.
index = aap_prod (sourcetype=fs_notification OR sourcetype=hadoop:prod:fm:journey) (action=add OR eventtype=fschange_add_file) | timechart count
and
index=aap_prod sourcetype="HDP:PROD:OOZIE" (":start:] with user-retry state" OR CASE("@end***]Action updated in DB!")) | rex "TOKEN\[\] APP\[(?<JobName>[^\]]*)" | search JobName=WF_danlaw_journey_hive | timechart count
Thanks.
The most simple approach is this:
index = aap_prod (sourcetype=fs_notification OR sourcetype=hadoop:prod:fm:journey) (action=add OR eventtype=fschange_add_file) | timechart count as countB
| appendcols [search index=aap_prod sourcetype="HDP:PROD:OOZIE" (":start:] with user-retry state" OR CASE("@end***]Action updated in DB!")) | rex "TOKEN\[\] APP\[(?<JobName>[^\]]*)" | search JobName=WF_danlaw_journey_hive | timechart count as countA]
If you clean up your searches a bit, for example extract the rex'd field from configuration, maybe store everything in eventtypes, etc., you could do something like this:
index=app_prod (eventtype=A OR eventtype=B) | eval class = if(eventtype="A", "A", "B") | timechart count by class
I've assumed that in case of A and B matching it should be counted for A... that's a matter of requirements though.
The most simple approach is this:
index = aap_prod (sourcetype=fs_notification OR sourcetype=hadoop:prod:fm:journey) (action=add OR eventtype=fschange_add_file) | timechart count as countB
| appendcols [search index=aap_prod sourcetype="HDP:PROD:OOZIE" (":start:] with user-retry state" OR CASE("@end***]Action updated in DB!")) | rex "TOKEN\[\] APP\[(?<JobName>[^\]]*)" | search JobName=WF_danlaw_journey_hive | timechart count as countA]
If you clean up your searches a bit, for example extract the rex'd field from configuration, maybe store everything in eventtypes, etc., you could do something like this:
index=app_prod (eventtype=A OR eventtype=B) | eval class = if(eventtype="A", "A", "B") | timechart count by class
I've assumed that in case of A and B matching it should be counted for A... that's a matter of requirements though.