<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Meaning of OSSEC dashboard pie graph count values in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Meaning-of-OSSEC-dashboard-pie-graph-count-values/m-p/69623#M44012</link>
    <description>&lt;P&gt;Hi, I just untarred 1.1.84 directly on top of my /opt/splunk/etc/apps/ossec directory (which was 1.1.82) and indeed my dashboard counts look reasonable now.  Thanks!&lt;/P&gt;</description>
    <pubDate>Fri, 08 Apr 2011 02:23:43 GMT</pubDate>
    <dc:creator>branchbunch</dc:creator>
    <dc:date>2011-04-08T02:23:43Z</dc:date>
    <item>
      <title>Meaning of OSSEC dashboard pie graph count values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Meaning-of-OSSEC-dashboard-pie-graph-count-values/m-p/69618#M44007</link>
      <description>&lt;P&gt;In the OSSEC dashboard, what do the count values mean for the elements of the various "Top N" pie graphs?  For example, at the moment in my "Top Signatures" pie graph, the count value for "Windows Error Event" is 42 but if I click on that element, the search results that come up exceed 250 records.  I'm running version 1.1.81 of OSSEC for Splunk 4, on Splunk 4.2.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2011 09:34:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Meaning-of-OSSEC-dashboard-pie-graph-count-values/m-p/69618#M44007</guid>
      <dc:creator>branchbunch</dc:creator>
      <dc:date>2011-03-29T09:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Meaning of OSSEC dashboard pie graph count values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Meaning-of-OSSEC-dashboard-pie-graph-count-values/m-p/69619#M44008</link>
      <description>&lt;P&gt;This is a known bug in builds prior to &lt;B&gt;1.1.83&lt;/B&gt;.&lt;/P&gt;

&lt;P&gt;It's showing the top 10 but the results are being clustered/grouped -- e.g., you get the top 10 users, but counting the user only once for a given reporting_host/severity/user.  When you drill down, it swaps out the search and you see the full result set.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2011 21:15:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Meaning-of-OSSEC-dashboard-pie-graph-count-values/m-p/69619#M44008</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2011-03-29T21:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: Meaning of OSSEC dashboard pie graph count values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Meaning-of-OSSEC-dashboard-pie-graph-count-values/m-p/69620#M44009</link>
      <description>&lt;P&gt;Thanks for the clarification.  So if it was a known bug previous to 1.1.82 then should I expect to see total (no clustered/grouped) alert counts in the "Top N" pie graphs and their respective tables?  I'm asking because I just upgraded to 1.1.82 and it seems to look the same as before.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2011 02:08:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Meaning-of-OSSEC-dashboard-pie-graph-count-values/m-p/69620#M44009</guid>
      <dc:creator>branchbunch</dc:creator>
      <dc:date>2011-03-31T02:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Meaning of OSSEC dashboard pie graph count values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Meaning-of-OSSEC-dashboard-pie-graph-count-values/m-p/69621#M44010</link>
      <description>&lt;P&gt;Looks like the fix didn't make into the SplunkBase upload. The fix is probably sitting in local -- once I get back to my dev box I'll re-upload and bump the version number.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2011 07:32:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Meaning-of-OSSEC-dashboard-pie-graph-count-values/m-p/69621#M44010</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2011-03-31T07:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Meaning of OSSEC dashboard pie graph count values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Meaning-of-OSSEC-dashboard-pie-graph-count-values/m-p/69622#M44011</link>
      <description>&lt;P&gt;If you haven't already, can you give the latest build on SplunkBase a try and see if it's still an issue for you?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2011 20:57:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Meaning-of-OSSEC-dashboard-pie-graph-count-values/m-p/69622#M44011</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2011-04-05T20:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: Meaning of OSSEC dashboard pie graph count values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Meaning-of-OSSEC-dashboard-pie-graph-count-values/m-p/69623#M44012</link>
      <description>&lt;P&gt;Hi, I just untarred 1.1.84 directly on top of my /opt/splunk/etc/apps/ossec directory (which was 1.1.82) and indeed my dashboard counts look reasonable now.  Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2011 02:23:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Meaning-of-OSSEC-dashboard-pie-graph-count-values/m-p/69623#M44012</guid>
      <dc:creator>branchbunch</dc:creator>
      <dc:date>2011-04-08T02:23:43Z</dc:date>
    </item>
  </channel>
</rss>

