Splunk Search

How do I put a line graph that shows data in both indexes into one graph?

WXY
Path Finder

Hi,

I want to get a line graph with two indexes of data.

My command is index=interface sourcetype="in_t"| timechart count and index=imp sourcetype="out_t"| timechart count

What should I do?

Tags (2)
0 Karma
1 Solution

renjith_nair
Legend

@WXY,

Try

(index=interface OR index=imp) (sourcetype="in_t" OR sourcetype="out_t")|timechart count by sourcetype
Happy Splunking!

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi WXY
try

(index=interface sourcetype="in_t") OR (index=imp sourcetype="out_t")
| timechart count

Bye.
Giuseppe

0 Karma

renjith_nair
Legend

@WXY,

Try

(index=interface OR index=imp) (sourcetype="in_t" OR sourcetype="out_t")|timechart count by sourcetype
Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...