Dashboards & Visualizations

How to use sparkline?

chrbar01
Explorer

Hello,

I've built some reports about CPU, memory and disk usage, and I'd like to display these reports as sparkline to obtain a compact view (and include more reports in the same view).

For example , my search is

sourcetype=infra subtype=system | timechart span=60m avg(cpu) by devicename

and the result is

_time              device1   device2     device3     device4
2016-10-12 14:00    1.666667    0.000000    5.000000    0.083333
2016-10-12 15:00    0.166667    0.000000    4.500000    0.000000
2016-10-12 16:00    0.000000    0.000000    2.916667    0.000000
2016-10-12 17:00    0.000000    0.083333    1.750000    0.000000
2016-10-12 18:00    0.000000    0.000000    1.000000    0.000000 

I've tried:

sourcetype=infra subtype=system | stats sparkline count, avg(cpu) by devicename
or
sourcetype=infra subtype=system | stats sparkline(avg(cpu)) by devicename

But I don't think that displays the good line chart!
I've also tried:

sourcetype=infra subtype=system | stats sparkline(avg(cpu),1m) by devicename

Could you tell me what is the variable "1m"?
Does it mean "1 month"?

Regards
Chris

0 Karma

chrbar01
Explorer

Thanks cmerriman.

Please, could you tell me if the syntax of my searchs with sparkline are correct, or if another will be better?
I've tried:

sourcetype=infra subtype=system | stats sparkline count, avg(cpu) by devicename
and
sourcetype=infra subtype=system | stats sparkline(avg(cpu)) by devicename
0 Karma

cmerriman
Super Champion

it depends on what you're trying to obtain

sourcetype=infra subtype=system | stats sparkline count, avg(cpu) by devicename

this search will give you a sparkline that shows the count over the timeframe you're specifying for each device

sourcetype=infra subtype=system | stats sparkline(avg(cpu)) by devicename

this search will give you a sparkline that shows the average cpu over the timeframe you're specifying for each device.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...