Dashboards & Visualizations

How to use sparkline?

chrbar01
Explorer

Hello,

I've built some reports about CPU, memory and disk usage, and I'd like to display these reports as sparkline to obtain a compact view (and include more reports in the same view).

For example , my search is

sourcetype=infra subtype=system | timechart span=60m avg(cpu) by devicename

and the result is

_time              device1   device2     device3     device4
2016-10-12 14:00    1.666667    0.000000    5.000000    0.083333
2016-10-12 15:00    0.166667    0.000000    4.500000    0.000000
2016-10-12 16:00    0.000000    0.000000    2.916667    0.000000
2016-10-12 17:00    0.000000    0.083333    1.750000    0.000000
2016-10-12 18:00    0.000000    0.000000    1.000000    0.000000 

I've tried:

sourcetype=infra subtype=system | stats sparkline count, avg(cpu) by devicename
or
sourcetype=infra subtype=system | stats sparkline(avg(cpu)) by devicename

But I don't think that displays the good line chart!
I've also tried:

sourcetype=infra subtype=system | stats sparkline(avg(cpu),1m) by devicename

Could you tell me what is the variable "1m"?
Does it mean "1 month"?

Regards
Chris

0 Karma

chrbar01
Explorer

Thanks cmerriman.

Please, could you tell me if the syntax of my searchs with sparkline are correct, or if another will be better?
I've tried:

sourcetype=infra subtype=system | stats sparkline count, avg(cpu) by devicename
and
sourcetype=infra subtype=system | stats sparkline(avg(cpu)) by devicename
0 Karma

cmerriman
Super Champion

it depends on what you're trying to obtain

sourcetype=infra subtype=system | stats sparkline count, avg(cpu) by devicename

this search will give you a sparkline that shows the count over the timeframe you're specifying for each device

sourcetype=infra subtype=system | stats sparkline(avg(cpu)) by devicename

this search will give you a sparkline that shows the average cpu over the timeframe you're specifying for each device.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...