<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to add sparkline and trend time to a single value visualization? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-sparkline-and-trend-time-to-a-single-value/m-p/299362#M19023</link>
    <description>&lt;P&gt;@dchalasani is there a reason you need to use sparkline instead of timechart ? Here is an example using timechart if you decide that is acceptable&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=aws sourcetype=description alert_risk_level=high | stats count as alert_risk_level by _time | eval alert_risk_level=alert_risk_level/1000  | eval alert_risk_level=round(alert_risk_level,2) | timechart span=1m max(alert_risk_level)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 17 May 2017 17:32:58 GMT</pubDate>
    <dc:creator>rphillips_splk</dc:creator>
    <dc:date>2017-05-17T17:32:58Z</dc:date>
    <item>
      <title>How to add sparkline and trend time to a single value visualization?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-sparkline-and-trend-time-to-a-single-value/m-p/299361#M19022</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I want to add a sparkline and trend time  for a single value.&lt;/P&gt;

&lt;P&gt;Can any one please help me how to do it? Below is the search string and source code.&lt;/P&gt;

&lt;P&gt;Please correct this.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=aws sourcetype=description alert_risk_level=high| stats count as alert_risk_level   |eval alert_risk_level=($alert_risk_level$/1000)|eval alert_risk_level=round(alert_risk_level,2)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Source code&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel&amp;gt;
  &amp;lt;single&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;index=aws sourcetype=description  | stats count as alert_risk_level  |eval alert_risk_level=($$alert_risk_level$$/1000)|eval alert_risk_level=round(alert_risk_level,2)&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;-60m@m&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="colorMode"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
    &amp;lt;option name="rangeColors"&amp;gt;["0x65a637","0x040751"]&amp;lt;/option&amp;gt;
    &amp;lt;option name="rangeValues"&amp;gt;[0]&amp;lt;/option&amp;gt;
    &amp;lt;option name="underLabel"&amp;gt;Risk Identified&amp;lt;/option&amp;gt;
    &amp;lt;option name="unit"&amp;gt;K&amp;lt;/option&amp;gt;
    &amp;lt;option name="unitPosition"&amp;gt;after&amp;lt;/option&amp;gt;
    &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;
    &amp;lt;option name="useThousandSeparators"&amp;gt;0&amp;lt;/option&amp;gt;
  &amp;lt;/single&amp;gt;
&amp;lt;/panel&amp;gt;
&amp;lt;panel&amp;gt;
  &amp;lt;single&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 17 May 2017 16:55:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-sparkline-and-trend-time-to-a-single-value/m-p/299361#M19022</guid>
      <dc:creator>dchalasani</dc:creator>
      <dc:date>2017-05-17T16:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to add sparkline and trend time to a single value visualization?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-sparkline-and-trend-time-to-a-single-value/m-p/299362#M19023</link>
      <description>&lt;P&gt;@dchalasani is there a reason you need to use sparkline instead of timechart ? Here is an example using timechart if you decide that is acceptable&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=aws sourcetype=description alert_risk_level=high | stats count as alert_risk_level by _time | eval alert_risk_level=alert_risk_level/1000  | eval alert_risk_level=round(alert_risk_level,2) | timechart span=1m max(alert_risk_level)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 17 May 2017 17:32:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-sparkline-and-trend-time-to-a-single-value/m-p/299362#M19023</guid>
      <dc:creator>rphillips_splk</dc:creator>
      <dc:date>2017-05-17T17:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to add sparkline and trend time to a single value visualization?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-sparkline-and-trend-time-to-a-single-value/m-p/299363#M19024</link>
      <description>&lt;P&gt;&lt;A href="https://image.slidesharecdn.com/splunkninjas6-151021001013-lva1-app6891/95/splunk-ninjas-new-features-pivot-and-search-dojo-12-638.jpg?cb=1445386361"&gt;https://image.slidesharecdn.com/splunkninjas6-151021001013-lva1-app6891/95/splunk-ninjas-new-features-pivot-and-search-dojo-12-638.jpg?cb=1445386361&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Please open the above link.&lt;/P&gt;

&lt;P&gt;Is this possible?&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 17:40:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-sparkline-and-trend-time-to-a-single-value/m-p/299363#M19024</guid>
      <dc:creator>dchalasani</dc:creator>
      <dc:date>2017-05-17T17:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to add sparkline and trend time to a single value visualization?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-sparkline-and-trend-time-to-a-single-value/m-p/299364#M19025</link>
      <description>&lt;P&gt;And can we change in source-code for sparkline..&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 18:14:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-sparkline-and-trend-time-to-a-single-value/m-p/299364#M19025</guid>
      <dc:creator>dchalasani</dc:creator>
      <dc:date>2017-05-17T18:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to add sparkline and trend time to a single value visualization?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-sparkline-and-trend-time-to-a-single-value/m-p/299365#M19026</link>
      <description>&lt;P&gt;Please convert the query to timechart instead of stats.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   &amp;lt;query&amp;gt;index=aws sourcetype=description | timechart count as alert_risk_level  |eval alert_risk_level=($$alert_risk_level$$/1000)|eval alert_risk_level=round(alert_risk_level,2)&amp;lt;/query&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You need to show Trend Indicator and Sparkline. You can do both of this directly from Splunk UI by Editing Single Value Properties from the &lt;STRONG&gt;Format&lt;/STRONG&gt; menu. Unless you have already done, requesting you to get &lt;STRONG&gt;Splunk 6.x Dashboard Examples App&lt;/STRONG&gt; from Splunkbase (&lt;A href="https://splunkbase.splunk.com/app/1603/"&gt;https://splunkbase.splunk.com/app/1603/&lt;/A&gt;) also refer to customizing Single Value documentation &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Viz/SingleValueFormatting"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Viz/SingleValueFormatting&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;If you want to do it through Simple XML, please refer to the following Documentation:&lt;BR /&gt;
look for &lt;STRONG&gt;trend&lt;/STRONG&gt; related configurations and set &lt;STRONG&gt;showSparkline&lt;/STRONG&gt; to true to show Spark Line.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML#single_value"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML#single_value&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 19:14:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-sparkline-and-trend-time-to-a-single-value/m-p/299365#M19026</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-05-17T19:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to add sparkline and trend time to a single value visualization?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-sparkline-and-trend-time-to-a-single-value/m-p/299366#M19027</link>
      <description>&lt;P&gt;here is source code example for single value element with sparkline and trend indicator:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;Single Value Element With Sparkline and Trend Indicator&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;title&amp;gt;With Sparkline and Trend Indicator&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=aws sourcetype=description alert_risk_level=high | timechart count as alert_risk_level  | eval alert_risk_level=alert_risk_level/1000  | eval alert_risk_level=round(alert_risk_level,2) &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="trendColorInterpretation"&amp;gt;standard&amp;lt;/option&amp;gt;
        &amp;lt;option name="trendDisplayMode"&amp;gt;absolute&amp;lt;/option&amp;gt;
        &amp;lt;option name="trendInterval"&amp;gt;-1h&amp;lt;/option&amp;gt;
        &amp;lt;option name="colorBy"&amp;gt;value&amp;lt;/option&amp;gt;
        &amp;lt;option name="colorMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="numberPrecision"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="showTrendIndicator"&amp;gt;1&amp;lt;/option&amp;gt;
        &amp;lt;option name="showSparkline"&amp;gt;1&amp;lt;/option&amp;gt;
        &amp;lt;option name="useColors"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="useThousandSeparators"&amp;gt;1&amp;lt;/option&amp;gt;
        &amp;lt;option name="underLabel"&amp;gt;Compared to an hour before&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;

  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 17 May 2017 19:38:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-sparkline-and-trend-time-to-a-single-value/m-p/299366#M19027</guid>
      <dc:creator>rphillips_splk</dc:creator>
      <dc:date>2017-05-17T19:38:06Z</dc:date>
    </item>
  </channel>
</rss>

