I have a checkbox in which user has to enter the hostname manually by himself.
So on the basis of the hostname entered the time chart for that hostname should be drawn automatically.
I am unable to incorporate this feature. Can anyone help in writing the search?
I am particularly new to Splunk.
If you capture the value entered in a field, say hostname, you can do something like your search |eval myhost=$hostname$ | timechart count by myhost
You can change based on what you want to plot in the timechart.
Can you please tell me how to capture the hostname,right now I am just able to enter the hostname in checkbox named filterhost.It still shows waiting for the input and no result is getting displayed.