<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create a dashboard panel to show more than two fields? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-a-dashboard-panel-to-show-more-than-two-fields/m-p/646075#M52758</link>
    <description>&lt;LI-CODE lang="markup"&gt;| eval Status=mvappend("Primary_Server: ".Primary_Server."-".Status_Primary,"Secondary_Server: ".Secondary_Server."-".Status_Secondary)
| stats count by Status&lt;/LI-CODE&gt;</description>
    <pubDate>Wed, 07 Jun 2023 09:46:07 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2023-06-07T09:46:07Z</dc:date>
    <item>
      <title>How to create a dashboard panel to show more than two fields?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-a-dashboard-panel-to-show-more-than-two-fields/m-p/645994#M52747</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I have got logs like below set which gives the VPN details like VPN_Name, Primary_Server, Secondary_Server and their status.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Log1:
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td &amp;gt;&amp;lt;b&amp;gt;&amp;lt;font color=olive&amp;gt;INDIA&amp;lt;/font&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;
&amp;lt;td &amp;gt;SNFGC_S_INDIA&amp;lt;/td&amp;gt;
&amp;lt;td &amp;gt;&amp;lt;b&amp;gt;&amp;lt;font color=green&amp;gt;gcgnamslap03p&amp;lt;/font&amp;gt;&amp;lt;/b&amp;gt; # &amp;lt;b&amp;gt;&amp;lt;font color=blue&amp;gt;gcgnamslap04p&amp;lt;/font&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;
&amp;lt;td &amp;gt;&amp;lt;b&amp;gt;&amp;lt;font color="green"&amp;gt;UP&amp;lt;/font&amp;gt;&amp;lt;/b&amp;gt;/&amp;lt;b&amp;gt;&amp;lt;font color=blue&amp;gt;SB&amp;lt;/font&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;

Log2:
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td &amp;gt;&amp;lt;b&amp;gt;&amp;lt;font color=olive&amp;gt;CHINA&amp;lt;/font&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;
&amp;lt;td &amp;gt;JBPMGC_S_CHINA&amp;lt;/td&amp;gt;
&amp;lt;td &amp;gt;&amp;lt;b&amp;gt;&amp;lt;font color=green&amp;gt;gcgnamslap03p&amp;lt;/font&amp;gt;&amp;lt;/b&amp;gt; # &amp;lt;b&amp;gt;&amp;lt;font color=blue&amp;gt;gcgnamslap04p&amp;lt;/font&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;
&amp;lt;td &amp;gt;&amp;lt;b&amp;gt;&amp;lt;font color="green"&amp;gt;UP&amp;lt;/font&amp;gt;&amp;lt;/b&amp;gt;/&amp;lt;b&amp;gt;&amp;lt;font color=blue&amp;gt;SB&amp;lt;/font&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;

Here I used the below query to extract the required fields:
... | rex field=_raw "\&amp;lt;tr\&amp;gt;\s+\&amp;lt;td\s\&amp;gt;\&amp;lt;b\&amp;gt;\&amp;lt;\w+\s\w+\=\w+\&amp;gt;(?P&amp;lt;Region&amp;gt;[^\&amp;lt;]+)\&amp;lt;\/\w+\&amp;gt;\&amp;lt;\/b\&amp;gt;\&amp;lt;\/td\&amp;gt;"
| rex field=_raw "\&amp;lt;tr\&amp;gt;\s+\&amp;lt;td\s\&amp;gt;\&amp;lt;b\&amp;gt;\&amp;lt;\w+\s\w+\=\w+\&amp;gt;[^\&amp;lt;]+\&amp;lt;\/\w+\&amp;gt;\&amp;lt;\/b\&amp;gt;\&amp;lt;\/td\&amp;gt;\s+\&amp;lt;td\s\&amp;gt;(?P&amp;lt;VPN_Name&amp;gt;[^\&amp;lt;]+)\&amp;lt;\/td\&amp;gt;"
| rex field=_raw "\&amp;lt;tr\&amp;gt;\s+\&amp;lt;td\s\&amp;gt;\&amp;lt;b\&amp;gt;\&amp;lt;\w+\s\w+\=\w+\&amp;gt;[^\&amp;lt;]+\&amp;lt;\/\w+\&amp;gt;\&amp;lt;\/b\&amp;gt;\&amp;lt;\/td\&amp;gt;\s+\&amp;lt;td\s\&amp;gt;[^\&amp;lt;]+\&amp;lt;\/td\&amp;gt;\s+\&amp;lt;td\s\&amp;gt;\&amp;lt;b\&amp;gt;\&amp;lt;\w+\s\w+\=\w+\&amp;gt;(?P&amp;lt;Primary_Server&amp;gt;[^\&amp;lt;]+)\&amp;lt;\/\w+\&amp;gt;\&amp;lt;\/b\&amp;gt;\s"
| rex field=_raw "\&amp;lt;tr\&amp;gt;\s+\&amp;lt;td\s\&amp;gt;\&amp;lt;b\&amp;gt;\&amp;lt;\w+\s\w+\=\w+\&amp;gt;[^\&amp;lt;]+\&amp;lt;\/\w+\&amp;gt;\&amp;lt;\/b\&amp;gt;\&amp;lt;\/td\&amp;gt;\s+\&amp;lt;td\s\&amp;gt;[^\&amp;lt;]+\&amp;lt;\/td\&amp;gt;\s+\&amp;lt;td\s\&amp;gt;\&amp;lt;b\&amp;gt;\&amp;lt;\w+\s\w+\=\w+\&amp;gt;[^\&amp;lt;]+\&amp;lt;\/\w+\&amp;gt;\&amp;lt;\/b\&amp;gt;\s\#\s\&amp;lt;b\&amp;gt;\&amp;lt;\w+\s\w+\=\w+\&amp;gt;(?P&amp;lt;Secondary_Server&amp;gt;[^\&amp;lt;]+)\&amp;lt;\/\w+\&amp;gt;\&amp;lt;\/b\&amp;gt;\&amp;lt;\/td\&amp;gt;"
| rex field=_raw "\&amp;lt;tr\&amp;gt;\s+\&amp;lt;td\s\&amp;gt;\&amp;lt;b\&amp;gt;\&amp;lt;\w+\s\w+\=\w+\&amp;gt;[^\&amp;lt;]+\&amp;lt;\/\w+\&amp;gt;\&amp;lt;\/b\&amp;gt;\&amp;lt;\/td\&amp;gt;\s+\&amp;lt;td\s\&amp;gt;[^\&amp;lt;]+\&amp;lt;\/td\&amp;gt;\s+\&amp;lt;td\s\&amp;gt;\&amp;lt;b\&amp;gt;\&amp;lt;\w+\s\w+\=\w+\&amp;gt;[^\&amp;lt;]+\&amp;lt;\/\w+\&amp;gt;\&amp;lt;\/b\&amp;gt;\s\#\s\&amp;lt;b\&amp;gt;\&amp;lt;\w+\s\w+\=\w+\&amp;gt;[^\&amp;lt;]+\&amp;lt;\/\w+\&amp;gt;\&amp;lt;\/b\&amp;gt;\&amp;lt;\/td\&amp;gt;\s+\&amp;lt;td\s\&amp;gt;\&amp;lt;b\&amp;gt;\&amp;lt;\w+\s\w+\=\"\w+\"\&amp;gt;(?P&amp;lt;Status_Primary&amp;gt;[^\&amp;lt;]+)\&amp;lt;\/\w+\&amp;gt;\&amp;lt;\/b\&amp;gt;\/\&amp;lt;b\&amp;gt;\&amp;lt;\w+\s\w+\=\w+\&amp;gt;(?P&amp;lt;Status_Secondary&amp;gt;[^\&amp;lt;]+)\&amp;lt;\/\w+\&amp;gt;\&amp;lt;\/b\&amp;gt;\&amp;lt;\/td\&amp;gt;"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to create a panel to show the details of Status_Primary (like how many are UP and how many are DOWN). For that I used added the query "| stats count by Status_Primary" to the above query and created a pie chart out of it.&lt;/P&gt;
&lt;P&gt;I also want to show in the same panel, which is the Primary_Server and which is the Secondary_Server. But I am not able to make a query to fill both data in the same panel.&lt;/P&gt;
&lt;P&gt;Please help to create a query to fill both the Status details and Server details in the same panel. Your kind help is highly appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you..!!&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 21:12:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-a-dashboard-panel-to-show-more-than-two-fields/m-p/645994#M52747</guid>
      <dc:creator>Mrig342</dc:creator>
      <dc:date>2023-06-06T21:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a dashboard panel to show more than two fields?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-a-dashboard-panel-to-show-more-than-two-fields/m-p/646030#M52751</link>
      <description>&lt;P&gt;Does this help&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval Status=mvappend("Primary_".Status_Primary,"Secondary_".Status_Secondary)
| stats count by Status&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 07 Jun 2023 07:19:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-a-dashboard-panel-to-show-more-than-two-fields/m-p/646030#M52751</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-07T07:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a dashboard panel to show more than two fields?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-a-dashboard-panel-to-show-more-than-two-fields/m-p/646067#M52755</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for your inputs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to change the query as below to show both the server name and status.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval Status=mvappend("Primary_Server: ".Primary_Server.Status_Primary,"Secondary_Server: ".Secondary_Server.Status_Secondary)
| stats count by Status&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And it gives the below table:&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Status&lt;/TD&gt;&lt;TD width="50%"&gt;count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Primary_Server: gcgnamslap03pDOWN&lt;/TD&gt;&lt;TD width="50%"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Primary_Server: gcgnamslap03pUP&lt;/TD&gt;&lt;TD width="50%"&gt;117&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Secondary_Server: gcgnamslap04pDOWN&lt;/TD&gt;&lt;TD width="50%"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Secondary_Server: gcgnamslap04pSB&lt;/TD&gt;&lt;TD width="50%"&gt;117&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;I want to put a hyphen (-) between the server name and the status to make the field value more meaningful like below:&lt;/P&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="405.5px"&gt;Status&lt;/TD&gt;&lt;TD width="239.5px"&gt;count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="405.5px"&gt;Primary_Server: gcgnamslap03p-DOWN&lt;/TD&gt;&lt;TD width="239.5px"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="405.5px"&gt;Primary_Server: gcgnamslap03p-UP&lt;/TD&gt;&lt;TD width="239.5px"&gt;117&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="405.5px"&gt;Secondary_Server: gcgnamslap04p-DOWN&lt;/TD&gt;&lt;TD width="239.5px"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="405.5px"&gt;Secondary_Server: gcgnamslap04p-SB&lt;/TD&gt;&lt;TD width="239.5px"&gt;117&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help to modify my query to get the desired output.&lt;/P&gt;&lt;P&gt;Thank you..!!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 09:28:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-a-dashboard-panel-to-show-more-than-two-fields/m-p/646067#M52755</guid>
      <dc:creator>Mrig342</dc:creator>
      <dc:date>2023-06-07T09:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a dashboard panel to show more than two fields?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-a-dashboard-panel-to-show-more-than-two-fields/m-p/646075#M52758</link>
      <description>&lt;LI-CODE lang="markup"&gt;| eval Status=mvappend("Primary_Server: ".Primary_Server."-".Status_Primary,"Secondary_Server: ".Secondary_Server."-".Status_Secondary)
| stats count by Status&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 07 Jun 2023 09:46:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-a-dashboard-panel-to-show-more-than-two-fields/m-p/646075#M52758</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-07T09:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a dashboard panel to show more than two fields?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-a-dashboard-panel-to-show-more-than-two-fields/m-p/646101#M52764</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you very much for your inputs. I am now able to get the dashboard panel in the desired manner.&lt;/P&gt;&lt;P&gt;Your kind help is highly appreciated.&lt;/P&gt;&lt;P&gt;Thank You..!!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 12:23:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-a-dashboard-panel-to-show-more-than-two-fields/m-p/646101#M52764</guid>
      <dc:creator>Mrig342</dc:creator>
      <dc:date>2023-06-07T12:23:33Z</dc:date>
    </item>
  </channel>
</rss>

