Dashboards & Visualizations

How to reference dimensions value in calculations?

cortega
Observer

Hi,

I have a metric with 1 dimension containing an integer value.

I need to apply some calculation to the metric based on the dimension value.

The formula to apply to each Data Point would be sth like this:


    metric_value*100/dimensionA_value

 

I have seen dimensions extensively used as filters but I was not able to find a way to reference the dimension value so that I can use it in a calculation like the one above.

 

Any idea, how could I accomplish that?

 

Thanks in advance

Cesar

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you show where this dimension is coming from in your events?

0 Karma

cortega
Observer

Thanks for your reply.
I am getting this metric from a monitor configured in the signalfx-agent installed in my hosts.

Not sure I am properly replying to your question (not very skilled in Splunk/SignalFX yet)... if not, please let me know.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you share some of your sample events in a code block </> - depersonalised of course?

0 Karma

cortega
Observer

Hi!

Sorry, but still not sure where to get that information.

I see a "Events" tab in my Chart and in the Metric view... but both contain no data.

I just exported my metric Data Table to CSV just in case it helps to make things clearer (here are a couple of data points for reference:

provider_network_netmask

metric (sf_metric)

appcode

Plot Name

provider_network_name

Value Prefix

Value Suffix

Fri Sep 02 2022 12:54:40 GMT+0200 (Central European Summer Time)

16

neutron.provider_networks.ip_count

xxx

neutron.provider_networks.ip_count

network1

 

 

10

24

neutron.provider_networks.ip_count

xxx

neutron.provider_networks.ip_count

network2

 

 

2

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

From your chart, if you "open in search", then change the mode to verbose, the events tab will be populated with the events from your search.

From your search, is dimensionA_value present as a field? If not, where does this value comes from?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...