I'd like to have a stacked column chart showing the number of successful and failed requests to URLs over time. Following the instructions at http://docs.splunk.com/Documentation/Splunk/latest/User/ReportOfMultipleDataSeries I can show success and failure separately, but ideally it would show 1 stacked column per URL split by success/failure. Is this possible?
The search I have so far is -
index="online"
| bucket _time span=1h
| stats count(eval(code="200")) as succ, count(eval(code!="200")) as fail by url, _time
| eval s1="success failure"
| makemv s1
| mvexpand s1
| eval yval=case(s1=="success",succ,s1=="failure",fail)
| eval series=s1+":"+url
| xyseries _time,series,yval
... View more