Dashboards & Visualizations

Dashboard Studio count input

jwhughes58
Contributor

I'm working with Dashboard Studio for the first time and I've got another question.

In the input on the Dashboard, I set this $servers_entered$.  I thought I had a solution for counting how many items are in $servers_entered$, but I found a case that failed.  This is what $servers_entered$ looks like.

host_1, host_2, host_3, host_4, ..., host_n

What I need is a way of counting how many entries are in $servers_entered$.  So far the commands I've tried have failed.  What would work?

TIA,

Joe

Labels (2)
0 Karma
1 Solution

jwhughes58
Contributor

This works.

| makeresults
| fields - _time
| eval hosts="$servers_entered$"
| makemv delim="," hosts
| eval count=mvcount(hosts)
| table count

View solution in original post

0 Karma

jwhughes58
Contributor

This works.

| makeresults
| fields - _time
| eval hosts="$servers_entered$"
| makemv delim="," hosts
| eval count=mvcount(hosts)
| table count
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Have you tried 

mvcount($servers_entered$)
0 Karma

jwhughes58
Contributor

@ITWhispererThanks, but those didn't work.  I tried both of these.

| makeresults
| fields - _time
| eval count=mvcount($servers_entered$)
mvcount($servers_entered$)

The first errors.  The second returns 0.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...