Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

using stats with a by on 2 fields works + but what about timechart with a by on 2 fields works

$
0
0
using stats with a by on 2 fields works `...| stats max(kpi1) as "kpi1" max(kpi2) as "kpi2" by field1 field2` but can I do the same using timechart (so far I don't think i can) `...| timechart max(kpi1) as "kpi1" max(kpi2) as "kpi2" by field1 field2` a work around I have is to use `strcat` which would be something like" `...| strcat field1 "-" field2 field1_2 | timechart max(kpi1) as "kpi1" max(kpi2) as "kpi2" by field1_2` Just wondering what other people do?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>