I am looking for examples on Custom Radar Chart visualization. The example on download page of SplunkBase shows some evals with static key values. Let's imagine that I have an index with these few details:
SourceIP, DestIP, protocol - pretty much purely non-numerical values.
Can you give an example how to attach those on chart visualization as keys being evaluated? Obviously I need to have them as counts (like amount of SourceIP's and so on) - how would you add them as evaluated keys?
Let's take SourceIP - I do have 5 of them on the list, DestIP's (there are 3) and protocol - well its either UDP or TCP, but count of each matter. How would you add them on the example to make it work?
In addition - is there a possibility to have, for example, eval key="CURRENT", then "PAST" and then "OBJECTIVE" - Per what I've tested, I am only able to have 2 evaluations on same chart.