Dashboards & Visualizations

How to add Visio into a dashboard to put live sankey diagram of events per second?

Contributor

Since our Splunk environment has grown, i wanted to build a Visio diagram and overlay sankey diagram of event counts, and live stats of servers.

  1. how do i import the diagram?
  2. how do add visuals over the diagram?
  3. has anyone done this before?
0 Karma
1 Solution

Communicator
  1. Install the sankey diagram from the store.

  2. You can only set the properties of the diagram, but if you click on the diagram from the front splunk page (should show on the left as a button) you get some good examples to work from. http://yoursplunkIP:8000/en-US/app/sankey_diagram_app/gallery

  3. I've experimented with it, if you check the examples by opening in search and viewing the statistics tab, you get inputlookup examples, these essentially read from a csv file in splunk but just for demonstration purposes, you need to focus on the table/fields it produces and write your query to reflect that.

Sankey diagrams are quite complex when comparing to the others, the three examples all require 4 fields, of which 2 are numeric and 2 are text, stats queries seem to be the base.

You can only really check the examples and base from there by building your stats based query...

View solution in original post

0 Karma

Esteemed Legend
0 Karma

Communicator
  1. Install the sankey diagram from the store.

  2. You can only set the properties of the diagram, but if you click on the diagram from the front splunk page (should show on the left as a button) you get some good examples to work from. http://yoursplunkIP:8000/en-US/app/sankey_diagram_app/gallery

  3. I've experimented with it, if you check the examples by opening in search and viewing the statistics tab, you get inputlookup examples, these essentially read from a csv file in splunk but just for demonstration purposes, you need to focus on the table/fields it produces and write your query to reflect that.

Sankey diagrams are quite complex when comparing to the others, the three examples all require 4 fields, of which 2 are numeric and 2 are text, stats queries seem to be the base.

You can only really check the examples and base from there by building your stats based query...

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

Hi sbattista09,
see in Splunk 6.x Dashboard Examples (https://splunkbase.splunk.com/app/1603/) "Image Overlay with Single Values".
There is an example for your need.
In other words, you have to modify your app CSS and address it in your dashboard.
Bye.
Giuseppe

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!