Dashboards & Visualizations

CPU Dashboard with Radial Gauge

Rhuen
New Member

Hy Guys,

i work since 3 Days with Splunk, now i was try to configure a Dashboard for a Server with the Radial Gauge Visualization.

But i dont know how, can anyone give me a example "search" code for this?
Server name: test-splunk , i have installed the Windows App, and Poll's the CPUTime every Second.

And now i will see the Radial Gauge in "Real Time" or every few seconds with the CPU % from the test-splunk server.

Thank You.

/edit

This is my search-code at this moment:
source=WMI:CPUTime host="test-splunk" PercentUserTime="*" | timechart avg(PercentUserTime)

I was try time range -1h to nothing, with this option i see a Column Grahpic from the last Hour.
When i Try the Radial Gauge i see only 0...when i change the Time Range to -1s, nothing happents, Radial Gauge is only 0.

greets

Tags (2)
0 Karma
1 Solution

dart
Splunk Employee
Splunk Employee

Here's an example based around the messages over 10 minutes in Splunk's internal log:

<?xml version='1.0' encoding='utf-8'?>
<dashboard>
  <label>testgauge</label>
  <row>
    <chart>
      <searchString>index=_internal | stats count </searchString>
      <title>internal</title>
      <earliestTime>rt-10m</earliestTime>
      <latestTime>rt</latestTime>
      <option name="charting.chart">radialGauge</option>
      <option name="count">10</option>
      <option name="displayRowNumbers">true</option>
    </chart>
  </row>
</dashboard>

You'll probably want to switch out the search for one which finds the CPUTime events, and then pipe to stats avg(CPUTime) or similar.

View solution in original post

0 Karma

dart
Splunk Employee
Splunk Employee

Here's an example based around the messages over 10 minutes in Splunk's internal log:

<?xml version='1.0' encoding='utf-8'?>
<dashboard>
  <label>testgauge</label>
  <row>
    <chart>
      <searchString>index=_internal | stats count </searchString>
      <title>internal</title>
      <earliestTime>rt-10m</earliestTime>
      <latestTime>rt</latestTime>
      <option name="charting.chart">radialGauge</option>
      <option name="count">10</option>
      <option name="displayRowNumbers">true</option>
    </chart>
  </row>
</dashboard>

You'll probably want to switch out the search for one which finds the CPUTime events, and then pipe to stats avg(CPUTime) or similar.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...