Dashboards & Visualizations

How to add Visio into a dashboard to put live sankey diagram of events per second?

sbattista09
Contributor

Since our Splunk environment has grown, i wanted to build a Visio diagram and overlay sankey diagram of event counts, and live stats of servers.

  1. how do i import the diagram?
  2. how do add visuals over the diagram?
  3. has anyone done this before?
0 Karma
1 Solution

jlvix1
Communicator
  1. Install the sankey diagram from the store.

  2. You can only set the properties of the diagram, but if you click on the diagram from the front splunk page (should show on the left as a button) you get some good examples to work from. http://yoursplunkIP:8000/en-US/app/sankey_diagram_app/gallery

  3. I've experimented with it, if you check the examples by opening in search and viewing the statistics tab, you get inputlookup examples, these essentially read from a csv file in splunk but just for demonstration purposes, you need to focus on the table/fields it produces and write your query to reflect that.

Sankey diagrams are quite complex when comparing to the others, the three examples all require 4 fields, of which 2 are numeric and 2 are text, stats queries seem to be the base.

You can only really check the examples and base from there by building your stats based query...

View solution in original post

0 Karma

woodcock
Esteemed Legend
0 Karma

jlvix1
Communicator
  1. Install the sankey diagram from the store.

  2. You can only set the properties of the diagram, but if you click on the diagram from the front splunk page (should show on the left as a button) you get some good examples to work from. http://yoursplunkIP:8000/en-US/app/sankey_diagram_app/gallery

  3. I've experimented with it, if you check the examples by opening in search and viewing the statistics tab, you get inputlookup examples, these essentially read from a csv file in splunk but just for demonstration purposes, you need to focus on the table/fields it produces and write your query to reflect that.

Sankey diagrams are quite complex when comparing to the others, the three examples all require 4 fields, of which 2 are numeric and 2 are text, stats queries seem to be the base.

You can only really check the examples and base from there by building your stats based query...

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi sbattista09,
see in Splunk 6.x Dashboard Examples (https://splunkbase.splunk.com/app/1603/) "Image Overlay with Single Values".
There is an example for your need.
In other words, you have to modify your app CSS and address it in your dashboard.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...