I have 3 fields and wanted to display separately but it is all stacked together. How can I separate the stacked chart? I used a search command of sourcetype="CurrentWeatherSGTraffic" OR sourcetype="ltaTraffic" [search sourcetype="CurrentWeatherSGTraffic" | dedup Location | fields Location] | timechart span=1m count(eval(current_summary="Thundery Showers" OR current_summary="Rain")) AS Rain, count(eval(Type="Accident")) as Accident, count(eval(Type="Heavy Traffic")) as HeavyTraffic by Location
It looks like its possible with advancedXML
http://splunk-base.splunk.com/answers/83966/multiple-stacked-columns-in-timechart
It looks like its possible with advancedXML
http://splunk-base.splunk.com/answers/83966/multiple-stacked-columns-in-timechart