I am new to Splunk
I need to know how to create bar chart count only by certain tags
For example event has tag=t1,t2,t3
I need create bar chart in x axis is only tag=t1, t2
Search
... | chart count by tag
Return chart with all tag (t1, t2, t3)values
Filter the tags using search or where command before your chart command.
... | where tag="t1" OR tag="t2" | chart count by tag
Filter the tags using search or where command before your chart command.
... | where tag="t1" OR tag="t2" | chart count by tag