Dashboards & Visualizations

Cumulative count and adding the events to the results overtime

deepuhassan
Explorer

Hi

i have a requirement to create a dashboard to represent total events

i have created a panel in the dashboard which refreshes for every 5 mins.

I need to add the new results to the existing count and show it on screen

i tried using streamstats and dashboard seems freezing when it tries to refresh 

any help or advise is if great help

Thanks

Sandeep

Labels (1)
0 Karma

tscroggins
Influencer

In most cases, your search time range should accommodate this directly.

For example, to show today's current count on refresh, set the time range to earliest=@d latest=now in whichever way makes sense for your dashboard:

| tstats count where sourcetype=example earliest=@d latest=now

If your solution is more complex than that, please provide an example.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...