Dashboards & Visualizations

Get a Single value for count of hosts for tstats query

neerajs_81
Builder

Hi, i have a requirement to create single value visual with trendline.  I have looked at sample queries on Dashboard studio examples hub.  Below is my base query.  

 

 

 

|tstats dc(host) as distinct_count where index=okta
sourcetype="OktaIM2:log"

 

Expected result:  Something like this

neerajs_81_0-1723617908025.png

I have been trying below 2 searches but neither of two is showing the expected result. 

 

|tstats dc(host) as distinct_host where index=okta sourcetype="OktaIM2:log"
| chart count(distinct_host) by _time
OR
|tstats dc(host) as distinct_host where index=okta sourcetype="OktaIM2:log"
| timechart count(distinct_host) by _time

 

If i try the below query without tstats,  it works but i need to use tstats from a performance point of view.

 

 

index=okta sourcetype="OktaIM2:log"
| chart dc(host) by _time span=1h

 

Any suggestion how to generate single value trendline with tstats?

 

Labels (3)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

If you want any sort of stat based on time, you should include it in the by clause. Try starting with something like this

|tstats dc(host) as distinct_host where index=okta sourcetype="OktaIM2:log" by _time

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

If you want any sort of stat based on time, you should include it in the by clause. Try starting with something like this

|tstats dc(host) as distinct_host where index=okta sourcetype="OktaIM2:log" by _time
0 Karma

neerajs_81
Builder

Thanks, didn't realize we could do a by clause with tstats as well.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...