It seems like this should be easy but I'm stumped. I have a total of 5 Applications that I am receiving logs for. I would like to create a dashboard panel with 5 pie charts (one for each app) showing the percentage of events each app logs out of the total events. I can get the correct numbers in a table and into a single pie chart or multiple bar charts but can't break out to 5 pie charts. Splunk Enterprise v7.1.0
mySearch...
| eventstats count as total
| eventstats count as "Apps" by app_name
| dedup app_name
| table app_name total Apps