Dashboards & Visualizations

Cumulative count and adding the events to the results overtime

deepuhassan
Explorer

Hi

i have a requirement to create a dashboard to represent total events

i have created a panel in the dashboard which refreshes for every 5 mins.

I need to add the new results to the existing count and show it on screen

i tried using streamstats and dashboard seems freezing when it tries to refresh 

any help or advise is if great help

Thanks

Sandeep

Labels (1)
0 Karma

tscroggins
Influencer

In most cases, your search time range should accommodate this directly.

For example, to show today's current count on refresh, set the time range to earliest=@d latest=now in whichever way makes sense for your dashboard:

| tstats count where sourcetype=example earliest=@d latest=now

If your solution is more complex than that, please provide an example.

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Observability - November 2025

Feature Highlight  Analyze your dimensions and metrics with Usage Analytics  To help optimize telemetry data ...

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...