Dashboards & Visualizations

Chart not showing up

lmalhoit
Explorer

Hi All, I'm pretty new to splunk. I was setting up my dashboard and tried to create a chart using the Top 5 Source Types saved search. It doesn't give an error or anything...just doesn't show anything. I've let it run for a day, to be on the safe side, but still nothing. When I click on View Results, it goes to the search and shows me the 5 source types, no problem. Here is the saved search:

index=_internal (source=/metrics.log OR source=\metrics.log) group=per_sourcetype_thruput | chart sum(kb) by series | sort -sum(kb) | head 5

Any suggestions?

Thanks!

Tags (3)

lmalhoit
Explorer

Your question about Flash got me thinking. I was using Chrome...so I tried Firefox and that seemed to fix it. Sorry for the stupid question!

Thanks!

0 Karma

thall79
Communicator

There is never a stupid question, glad you were able to fix it.

0 Karma

thall79
Communicator

Just curious are you building a simple dashboard? If so did you try and select Data table from the panel style drop down instead of chart to see if you get results on that dashboard?

Next question are you able to see other flash charts in Splunk?

And what version of Splunk are you using?

Travis.

lmalhoit
Explorer

I believe it is just a simple dashboard. I did select Chart in the drop down, though. I am able to see other charts when I do a Search...I can see the bar graphs, for example.
This is version 4.1.6

Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...