When viewing distribution graphs, you can overlay another variable on top of the current graph.
Compare two values to show relationships. For example, you can compare total events and average severity. This feature provides valuable data comparisons over time, at a glance. And by combining results onto a single distribution graph, you can save space when creating large views.
The comparison is limited to the same type as the selected query. For example, if an event query is selected, you can compare with the fields from the event table only, not the flow or assets and vulnerabilities table.
When you apply the query parameters to the distribution chart, it runs its query as normal. If the comparison field is enabled, a secondary query is run at the same time. The distribution component displays the data for both data sets on the same graph, but uses two separate vertical axes. If you change the chart type, both sets of data continue to display.