Dashboards & Visualizations

Can i split my results in to certain no of individual modules ?

rakesh_498115
Motivator

Hi,

I am using my query something like this...

sourcetype="x" | stats avg(duration) by SERVER

my output is as follows :

SERVER avg(duration)
M1 12
M2 54
M3 67

These Servers information may changed according to the real time logs.i.e they may inrease...

My requirement now is i need to display these results in separate singlevalue modules..

ie M1 one singlevalue moudule showing 12 and so on...

So i wat i need to dynamically generate certain no of single value fields basin on my search command ..or basin on my search results which clearly tell they are three servers for the above mentioned scneraio..

Please help...Can we do it in SPlunk ???

Tags (3)
0 Karma

Kate_Lawrence-G
Contributor

I think you would have to create a 3 different searches (or a mabye a master searcj with some post-processes to display results...?) and display these results individually.

The SingleValue module is pretty limited at what it can display:
SingleValue

(extends DispatchingModule) This module waits for the search to complete and then renders a single field from the first row of the results

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...