Dashboards & Visualizations

Add additional ad-hoc data (one time input) to create graphs in dashboard

abhivar3
New Member

Hello Guys,

I am splunk end user and have limited access to splunk app UI, I am quite new to this and would require your help.
Our admin team gets the data loaded into our splunk app from our servers, from that data I have created dashboard which has graphs for various things.

But the log does not contain certain information for which I want to create graph so would like to supply this new raw data manually. I searched online and can see this can be done by adding/installing add-ons but as I said I have limited access.

Can anyone suggest how can I achieve same?
I came across Text input [tokens], is it possible to supply my data in some format in the text input box and then create a graph out of it. For example I have to create graph of some ticket count per day, I can supply data in below format and would like to create a bar chart showing ticket count per day.

01.05.2018:3|02.05.2018:12|03.05.2018:21|04.05.2018:41|05.05.2018:12|06.05.2018:22|07.05.2018:51|08.05.2018:5

Any help will be much appreciated.

0 Karma

somesoni2
Revered Legend

How about you put this data in a lookup file and upload to Splunk? (you should've access to create private lookups) You can use a text input as well but it will have limited input string length and there would a further restriction of browser's URL length. For reference, here is what your search would look like if using text input to get that colon/pipe separate data

| gentimes start=-1 | eval temp="$YourToken$" | table temp | makemv temp delim="|" | mvexpand temp | rex field=temp "(?<Date>.+)\:(?<count>.+)" | eval _time=strptime(Date,"%m.%d.%Y") | timechart span=1d sum(count) as count
0 Karma

abhivar3
New Member

Thanks somesoni2 for your suggestion, let me try both of these out. Will come back to you with updates.

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...