HI!
What's the easiest way to create a time-chart and stats table with same query so I can create a dashboard, have a chart on the left, and stats table beside it without creating a seperate search?
Once I introduce the stats command, the time-chart comes back with no results.
Thanks!
You can utilize Splunk's PostProcess to create two outputs (table and chart) from virtually same query. In PostProcess search your can just format the output.
"_time" field is required to use "timechart" command. Are you ok?
It is easy to answer if there is a XML(or search statement).