Dashboards & Visualizations

Can I use data from two different metrics in the same dashboard?

suryagogi
New Member

I have two different metrics: one metric tells if a device is online. Another metric tells if a device has a process crash. How do I get average crashes per device installed? For example, I can get number of unique devices online in the last seven days. I can also get number of process crashes in the last seven days. How do I calculate average number of process crashes per device installed?

0 Karma

cmerriman
Super Champion

it would be helpful if you could give a little more detail. for example sourcetypes/indexes/etc. and field names so that we can see what each event has and help write a query surrounding that. also, sample data is really helpful.

that said, something like this might help get you started:

index=online_devices OR index=process_crashes earliest=-7d|stats count(eval(index="online_devices")) as online_devices count(eval(index="process_crashes")) as process_crashes|eval crashes_per_device=round(process_crashes/online_devices,2)
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...