<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to build a logic to create a dashboard with out using the non-transform command. in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-build-a-logic-to-create-a-dashboard-with-out-using-the/m-p/518479#M34792</link>
    <description>&lt;P&gt;Hi All, I have created a dashboard with four panels and used a base query and sub query. But in the base query&amp;nbsp; i have used the non-transforming command.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Base query details&lt;/U&gt;&lt;/P&gt;&lt;P&gt;index=test sourcetype=x_service component=x_component |&amp;nbsp; eval result=case(result="Passed","CompletePassed",result="Failed","CompletedFailed",isnotnull(result),result,isnull(result),null) | eventstats lastest(result) as result latest(status) as finalStatus earliest(_time) as Earliest latest(_time) as Latest by transId,component&amp;nbsp; | eval Final_result=case(isnull(result) AND isnotnull(finalStatus),finalStatus,isnotnull(result),result,isnull(result) AND isnull(finalStatus),"MissingStatus") | fields&amp;nbsp; _time, transId,component,result,Final_result,status,finalStatus,message,duration&lt;/P&gt;&lt;P&gt;In one of the panels I have used sub query to find the average duration to complete the transaction.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Average duration to complete the transaction&amp;nbsp;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;| timechart span=30m avg(duration)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using the above base query and sub query, I am able to get the output but it seems it is not best practice to use the non-transforming commands in dashboards,&amp;nbsp; so used stats command instead of event stats command in base search and got the output.&lt;/P&gt;&lt;P&gt;Similarly to calculate the average duration to complete the transaction created another base query for that panel and used&amp;nbsp; the stats/timechart unable to get the output.&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=test sourcetype=x_service component=x_component | stats earliest (_time) as Earliest&amp;nbsp; &amp;nbsp;latest(_time) as Latest by correlationId | eval duration= Earliest-Latest | timechart span=30m avg(duration)&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;unable to get the output.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when we use the eventstats commands I am&amp;nbsp; getting the output.&lt;/P&gt;&lt;P&gt;index=test sourcetype=x_service component=x_component | eventstats earliest (_time) as Earliest&amp;nbsp; &amp;nbsp;latest(_time) as Latest by correlationId | eval duration= Earliest-Latest | timechart span=30m avg(duration)&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question is how to write the sub query using the base query.&lt;/P&gt;&lt;P&gt;Thanks in advance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Sep 2020 15:57:29 GMT</pubDate>
    <dc:creator>Hemnaath</dc:creator>
    <dc:date>2020-09-08T15:57:29Z</dc:date>
    <item>
      <title>How to build a logic to create a dashboard with out using the non-transform command.</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-build-a-logic-to-create-a-dashboard-with-out-using-the/m-p/518479#M34792</link>
      <description>&lt;P&gt;Hi All, I have created a dashboard with four panels and used a base query and sub query. But in the base query&amp;nbsp; i have used the non-transforming command.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Base query details&lt;/U&gt;&lt;/P&gt;&lt;P&gt;index=test sourcetype=x_service component=x_component |&amp;nbsp; eval result=case(result="Passed","CompletePassed",result="Failed","CompletedFailed",isnotnull(result),result,isnull(result),null) | eventstats lastest(result) as result latest(status) as finalStatus earliest(_time) as Earliest latest(_time) as Latest by transId,component&amp;nbsp; | eval Final_result=case(isnull(result) AND isnotnull(finalStatus),finalStatus,isnotnull(result),result,isnull(result) AND isnull(finalStatus),"MissingStatus") | fields&amp;nbsp; _time, transId,component,result,Final_result,status,finalStatus,message,duration&lt;/P&gt;&lt;P&gt;In one of the panels I have used sub query to find the average duration to complete the transaction.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Average duration to complete the transaction&amp;nbsp;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;| timechart span=30m avg(duration)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using the above base query and sub query, I am able to get the output but it seems it is not best practice to use the non-transforming commands in dashboards,&amp;nbsp; so used stats command instead of event stats command in base search and got the output.&lt;/P&gt;&lt;P&gt;Similarly to calculate the average duration to complete the transaction created another base query for that panel and used&amp;nbsp; the stats/timechart unable to get the output.&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=test sourcetype=x_service component=x_component | stats earliest (_time) as Earliest&amp;nbsp; &amp;nbsp;latest(_time) as Latest by correlationId | eval duration= Earliest-Latest | timechart span=30m avg(duration)&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;unable to get the output.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when we use the eventstats commands I am&amp;nbsp; getting the output.&lt;/P&gt;&lt;P&gt;index=test sourcetype=x_service component=x_component | eventstats earliest (_time) as Earliest&amp;nbsp; &amp;nbsp;latest(_time) as Latest by correlationId | eval duration= Earliest-Latest | timechart span=30m avg(duration)&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question is how to write the sub query using the base query.&lt;/P&gt;&lt;P&gt;Thanks in advance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 15:57:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-build-a-logic-to-create-a-dashboard-with-out-using-the/m-p/518479#M34792</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2020-09-08T15:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to build a logic to create a dashboard with out using the non-transform command.</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-build-a-logic-to-create-a-dashboard-with-out-using-the/m-p/518513#M34794</link>
      <description>Hi&lt;BR /&gt;Add to the end of base query | fields * if you cannot use transforming commands. Usually this helps to use any fields on sub query. And remember the max amount of event when you are using non transforming query!&lt;BR /&gt;R. Ismo</description>
      <pubDate>Tue, 08 Sep 2020 18:56:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-build-a-logic-to-create-a-dashboard-with-out-using-the/m-p/518513#M34794</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-09-08T18:56:09Z</dc:date>
    </item>
  </channel>
</rss>

