Dashboards & Visualizations

Extended Dashboard

Christian
Path Finder

hi @all

i've got files like this:

2011-03-20 20:36:12 server=sxxxxx env=DEV os=LINUX stateDiskPath=0 stateRouting=1 stateBackup=1 statePuppet=1 stateTotal=1

First: I don't know how I can change the host-field to servername

Second: Can I create an extended Dashboard like:

Server1 Env OS  state1  state2  state3  state4  stateTotal

The states should be like green and red bubbles.

Is this possible and how can I do this? I'm new in splunk and havn't an idea if this is possible or not.

Thanks for replay!

Tags (1)
0 Karma
1 Solution

hazekamp
Builder

You can change the host field at index time with a "TRANSFORMS" property:

## props.conf
[mysourcetype]
TRANSFORMS-force_host_for_mysourcetype = force_host_for_mysourcetype

## transforms.conf
[force_host_for_mysourcetype]
DEST_KEY = MetaData:Host
REGEX = \d{4}-\d{2}-\d{2}\s+\d{2}:\d{2}:\d{2}\s+server=(\S+)
FORMAT = host::$1

You can create a dashboard using the following search. The dashboard creation itself can be a bit tricky. We may have to incorporate the "rangemap" search command and map 0=low 1=severe.

sourcetype=mysourcetype | stats last(state1) as state1, last(state2) as state2, last(state3) as state3, last(state4) as state4 by server, env, os | addtotals fieldname=stateTotal

View solution in original post

hazekamp
Builder

You can change the host field at index time with a "TRANSFORMS" property:

## props.conf
[mysourcetype]
TRANSFORMS-force_host_for_mysourcetype = force_host_for_mysourcetype

## transforms.conf
[force_host_for_mysourcetype]
DEST_KEY = MetaData:Host
REGEX = \d{4}-\d{2}-\d{2}\s+\d{2}:\d{2}:\d{2}\s+server=(\S+)
FORMAT = host::$1

You can create a dashboard using the following search. The dashboard creation itself can be a bit tricky. We may have to incorporate the "rangemap" search command and map 0=low 1=severe.

sourcetype=mysourcetype | stats last(state1) as state1, last(state2) as state2, last(state3) as state3, last(state4) as state4 by server, env, os | addtotals fieldname=stateTotal

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...