Dashboards & Visualizations

Base Searches

WanLohnston
Explorer

Hi, 

I was wondering if it's at all possible to use a very broad query as a base search and then use queries to filter it down? 

Example would be a base search of all IDs, then a query using that base search to filter it down by a particular group. 

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

The important point to remember about base searches is that they are limited in volume and sometimes you can make your overall dashboard performance worse.  They are not intended as a vast lookup.

Given that, yes you can make a somewhat broad search, for example

index=abc
| stats count by id a b c

and then have 4 sub searches that do

1. | stats dc(id) as ids

2. | stats sum(count) as count by a

3. | stats sum(count) as count by b

4. | stats sum(count) as count by c

Maybe  if you gave a bit more detail and some of the search we could better advise if makes sense.

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @WanLohnston ,

yes, it's possible:

you must create a base search, with all the levels of complication and then use it as the starting point for the searches in each panel.

for more details see at https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/simple-xml-dashboards/9.4...

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...