Dashboards & Visualizations

Can I use data from two different metrics in the same dashboard?

suryagogi
New Member

I have two different metrics: one metric tells if a device is online. Another metric tells if a device has a process crash. How do I get average crashes per device installed? For example, I can get number of unique devices online in the last seven days. I can also get number of process crashes in the last seven days. How do I calculate average number of process crashes per device installed?

0 Karma

cmerriman
Super Champion

it would be helpful if you could give a little more detail. for example sourcetypes/indexes/etc. and field names so that we can see what each event has and help write a query surrounding that. also, sample data is really helpful.

that said, something like this might help get you started:

index=online_devices OR index=process_crashes earliest=-7d|stats count(eval(index="online_devices")) as online_devices count(eval(index="process_crashes")) as process_crashes|eval crashes_per_device=round(process_crashes/online_devices,2)
Get Updates on the Splunk Community!

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...