<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to display pattern tab result in report in dashboard? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260752#M45223</link>
    <description>&lt;P&gt;result are different from pattern tab  after append this command&lt;/P&gt;

&lt;P&gt;&lt;A href="https://drive.google.com/file/d/0Bxs_ao6uuBDUR1g1djdIZHVhejQ/view?usp=sharing"&gt;https://drive.google.com/file/d/0Bxs_ao6uuBDUR1g1djdIZHVhejQ/view?usp=sharing&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://drive.google.com/file/d/0Bxs_ao6uuBDURUhHdDNlUEh3RUU/view?usp=sharing"&gt;https://drive.google.com/file/d/0Bxs_ao6uuBDURUhHdDNlUEh3RUU/view?usp=sharing&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Aug 2016 09:38:06 GMT</pubDate>
    <dc:creator>cyberportnoc</dc:creator>
    <dc:date>2016-08-31T09:38:06Z</dc:date>
    <item>
      <title>how to display pattern tab result in report in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260750#M45221</link>
      <description>&lt;P&gt;how to display pattern tab result in report in dashboard?&lt;BR /&gt;
i click save as report and find no option about showing pattern tab result&lt;/P&gt;

&lt;P&gt;is there any command equivalent to show the same result as pattern tab&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2016 06:47:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260750#M45221</guid>
      <dc:creator>cyberportnoc</dc:creator>
      <dc:date>2016-08-30T06:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: how to display pattern tab result in report in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260751#M45222</link>
      <description>&lt;P&gt;There is no direct way to display the patterns tab the way it is formatted in the Search and Reporting app in a dashboard.&lt;BR /&gt;
But... the Patterns tab is produced by running a &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.4.2/SearchReference/Cluster" target="_blank"&gt;cluster command&lt;/A&gt; under the covers. You can check the _audit index after selecting the patterns tab and you will see something like this (I used a search on the _internal index when selecting patterns):&lt;BR /&gt;
 &lt;CODE&gt;index=_internal | cluster t=0.3 labelonly=true labelfield=_patterns match=termset | findkeywords labelfield=_patterns dedup=true&lt;/CODE&gt;&lt;BR /&gt;
You can start here and format the output to satisfy your display needs.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:47:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260751#M45222</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2020-09-29T10:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: how to display pattern tab result in report in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260752#M45223</link>
      <description>&lt;P&gt;result are different from pattern tab  after append this command&lt;/P&gt;

&lt;P&gt;&lt;A href="https://drive.google.com/file/d/0Bxs_ao6uuBDUR1g1djdIZHVhejQ/view?usp=sharing"&gt;https://drive.google.com/file/d/0Bxs_ao6uuBDUR1g1djdIZHVhejQ/view?usp=sharing&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://drive.google.com/file/d/0Bxs_ao6uuBDURUhHdDNlUEh3RUU/view?usp=sharing"&gt;https://drive.google.com/file/d/0Bxs_ao6uuBDURUhHdDNlUEh3RUU/view?usp=sharing&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2016 09:38:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260752#M45223</guid>
      <dc:creator>cyberportnoc</dc:creator>
      <dc:date>2016-08-31T09:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: how to display pattern tab result in report in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260753#M45224</link>
      <description>&lt;P&gt;find found no _audit index in pattern tab or search events tab, where is it?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2016 01:45:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260753#M45224</guid>
      <dc:creator>cyberportnoc</dc:creator>
      <dc:date>2016-09-01T01:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: how to display pattern tab result in report in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260754#M45225</link>
      <description>&lt;P&gt;i append index=_internal or index=_audit&lt;/P&gt;

&lt;P&gt;&lt;A href="https://drive.google.com/file/d/0Bxs_ao6uuBDUd2xMcXdyY3JkR1E/view?usp=sharing" target="_blank"&gt;https://drive.google.com/file/d/0Bxs_ao6uuBDUd2xMcXdyY3JkR1E/view?usp=sharing&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://drive.google.com/file/d/0Bxs_ao6uuBDUOWdnYXl3LXhpSzA/view?usp=sharing" target="_blank"&gt;https://drive.google.com/file/d/0Bxs_ao6uuBDUOWdnYXl3LXhpSzA/view?usp=sharing&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;but no result&lt;/P&gt;

&lt;P&gt;autojoin='1' buckets=300 ttl=600 max_count=500000 maxtime=8640000 enable_lookups='1'&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:48:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260754#M45225</guid>
      <dc:creator>cyberportnoc</dc:creator>
      <dc:date>2020-09-29T10:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: how to display pattern tab result in report in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260755#M45226</link>
      <description>&lt;P&gt;is there any updated in your answer? &lt;/P&gt;

&lt;P&gt;after tried to append index=_audit  or index=_internal , still can not create the same result as pattern tab&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:49:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260755#M45226</guid>
      <dc:creator>cyberportnoc</dc:creator>
      <dc:date>2020-09-29T10:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: how to display pattern tab result in report in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260756#M45227</link>
      <description>&lt;P&gt;I was using the &lt;EM&gt;internal index as an &lt;STRONG&gt;example&lt;/STRONG&gt; to show you what is being executed under the covers by the patterns tab. You would obviously have to use the index that contains your data for which you want to identify the patterns. Which index contains the data for your sourcetype=access&lt;/EM&gt;*? That's the one you need to search. If it's searched by default, just remove index=_internal&lt;/P&gt;

&lt;P&gt;Your results from 2 days ago were different, because you looked at the patterns tab for a search over your data, but added index=_internal to the search that used the cluster command. The timeframes were slightly different as well.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2016 16:31:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260756#M45227</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2016-09-02T16:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: how to display pattern tab result in report in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260757#M45228</link>
      <description>&lt;P&gt;Just adding one note because I have seen this discussion as I was looking for the same answer.&lt;/P&gt;

&lt;P&gt;Going in &lt;STRONG&gt;Settings &amp;gt;&amp;gt; Monitoring Console &amp;gt;&amp;gt; Search &amp;gt;&amp;gt; Activity &amp;gt;&amp;gt; Search Usage Statistics: Instance&lt;/STRONG&gt; and then selecting the option "Only Ad Hoc Searches" = NO, you can find the search triggered by Splunk when you click on "Pattern" tab:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| loadjob 1233886270.2 events=true require_finished=false | cluster t=0.8 labelonly=true labelfield=_patterns match=termset | findkeywords labelfield=_patterns dedup=true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;this is exactly what is done in the background (where 1233886270.2 is the search job id)&lt;/P&gt;

&lt;P&gt;Then if you want to recreate the same result, approximately you have to attach this to your search&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| cluster t=0.8 labelonly=t showcount=t labelfield=_patterns match=termset
| findkeywords labelfield=_patterns dedup=true
| search confidence&amp;gt;0
| fields - search
| sort -percentMatched
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Just wondering/checking how exactly it is sorting the results, and how is calculating the number of events matched&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 19:16:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-display-pattern-tab-result-in-report-in-dashboard/m-p/260757#M45228</guid>
      <dc:creator>edoardo_vicendo</dc:creator>
      <dc:date>2019-03-07T19:16:12Z</dc:date>
    </item>
  </channel>
</rss>

