Splunk Search

Is it possible to genereate parallell time charts liks this?

sune43
Engager

IS is possible to draw charts in Splunk that can show multi-channel data in the same chart? Similar to the multi-channel chart below?

I want to correllate time events from different systems and figure out when things happend in correlation with other events

alt text

Tags (2)

Ayn
Legend

Not sure if this what you're after, but timechart has a split-by directive so you could chart a field split by some term, so for instance

... | timechart count by Task

would give you multiple lines, one for each value for Task.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...