Dashboards & Visualizations

How to add Visio into a dashboard to put live sankey diagram of events per second?

sbattista09
Contributor

Since our Splunk environment has grown, i wanted to build a Visio diagram and overlay sankey diagram of event counts, and live stats of servers.

  1. how do i import the diagram?
  2. how do add visuals over the diagram?
  3. has anyone done this before?
0 Karma
1 Solution

jlvix1
Communicator
  1. Install the sankey diagram from the store.

  2. You can only set the properties of the diagram, but if you click on the diagram from the front splunk page (should show on the left as a button) you get some good examples to work from. http://yoursplunkIP:8000/en-US/app/sankey_diagram_app/gallery

  3. I've experimented with it, if you check the examples by opening in search and viewing the statistics tab, you get inputlookup examples, these essentially read from a csv file in splunk but just for demonstration purposes, you need to focus on the table/fields it produces and write your query to reflect that.

Sankey diagrams are quite complex when comparing to the others, the three examples all require 4 fields, of which 2 are numeric and 2 are text, stats queries seem to be the base.

You can only really check the examples and base from there by building your stats based query...

View solution in original post

0 Karma

woodcock
Esteemed Legend
0 Karma

jlvix1
Communicator
  1. Install the sankey diagram from the store.

  2. You can only set the properties of the diagram, but if you click on the diagram from the front splunk page (should show on the left as a button) you get some good examples to work from. http://yoursplunkIP:8000/en-US/app/sankey_diagram_app/gallery

  3. I've experimented with it, if you check the examples by opening in search and viewing the statistics tab, you get inputlookup examples, these essentially read from a csv file in splunk but just for demonstration purposes, you need to focus on the table/fields it produces and write your query to reflect that.

Sankey diagrams are quite complex when comparing to the others, the three examples all require 4 fields, of which 2 are numeric and 2 are text, stats queries seem to be the base.

You can only really check the examples and base from there by building your stats based query...

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi sbattista09,
see in Splunk 6.x Dashboard Examples (https://splunkbase.splunk.com/app/1603/) "Image Overlay with Single Values".
There is an example for your need.
In other words, you have to modify your app CSS and address it in your dashboard.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...