|
I have log entries that contain, among other things, fields called AcctID and exec_time. I have a user who wants to do, essentially:
Since I know this to not be directly possible in 4.1, I went to the strategy laid out in http://www.splunk.com/base/Documentation/4.1.6/User/ReportOfMultipleDataSeries. My search ends up being:
And I get results as expected, like:
But when I add the final What am I missing? |
|
I just walked through the docs myself using some access data use cases and it looks to me like there are mistakes in the documentation. The docs give this example:
The main mistake is that the stats should be There's also a second mistake although it's minor and it doesnt seem to have tripped you up at all -- the I think you were following the docs perfectly, but the docs themselves got garbled at some point. It happens. So try this:
docs are fixed.
(20 Mar '11, 17:46)
gkanapathy ♦
gerald's the best. =)
(21 Mar '11, 05:04)
nick ♦
That's the ticket. Thanks, Doctor Nick!
(21 Mar '11, 17:08)
pde23
|
