Dashboards & Visualizations

Get a Single value for count of hosts for tstats query

neerajs_81
Builder

Hi, i have a requirement to create single value visual with trendline.  I have looked at sample queries on Dashboard studio examples hub.  Below is my base query.  

 

 

 

|tstats dc(host) as distinct_count where index=okta
sourcetype="OktaIM2:log"

 

Expected result:  Something like this

neerajs_81_0-1723617908025.png

I have been trying below 2 searches but neither of two is showing the expected result. 

 

|tstats dc(host) as distinct_host where index=okta sourcetype="OktaIM2:log"
| chart count(distinct_host) by _time
OR
|tstats dc(host) as distinct_host where index=okta sourcetype="OktaIM2:log"
| timechart count(distinct_host) by _time

 

If i try the below query without tstats,  it works but i need to use tstats from a performance point of view.

 

 

index=okta sourcetype="OktaIM2:log"
| chart dc(host) by _time span=1h

 

Any suggestion how to generate single value trendline with tstats?

 

Labels (3)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

If you want any sort of stat based on time, you should include it in the by clause. Try starting with something like this

|tstats dc(host) as distinct_host where index=okta sourcetype="OktaIM2:log" by _time

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

If you want any sort of stat based on time, you should include it in the by clause. Try starting with something like this

|tstats dc(host) as distinct_host where index=okta sourcetype="OktaIM2:log" by _time
0 Karma

neerajs_81
Builder

Thanks, didn't realize we could do a by clause with tstats as well.

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...