Dashboards & Visualizations

Cumulative count and adding the events to the results overtime

deepuhassan
Explorer

Hi

i have a requirement to create a dashboard to represent total events

i have created a panel in the dashboard which refreshes for every 5 mins.

I need to add the new results to the existing count and show it on screen

i tried using streamstats and dashboard seems freezing when it tries to refresh 

any help or advise is if great help

Thanks

Sandeep

Labels (1)
0 Karma

tscroggins
Influencer

In most cases, your search time range should accommodate this directly.

For example, to show today's current count on refresh, set the time range to earliest=@d latest=now in whichever way makes sense for your dashboard:

| tstats count where sourcetype=example earliest=@d latest=now

If your solution is more complex than that, please provide an example.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...