Dashboards & Visualizations

How to use sparkline?

chrbar01
Explorer

Hello,

I've built some reports about CPU, memory and disk usage, and I'd like to display these reports as sparkline to obtain a compact view (and include more reports in the same view).

For example , my search is

sourcetype=infra subtype=system | timechart span=60m avg(cpu) by devicename

and the result is

_time              device1   device2     device3     device4
2016-10-12 14:00    1.666667    0.000000    5.000000    0.083333
2016-10-12 15:00    0.166667    0.000000    4.500000    0.000000
2016-10-12 16:00    0.000000    0.000000    2.916667    0.000000
2016-10-12 17:00    0.000000    0.083333    1.750000    0.000000
2016-10-12 18:00    0.000000    0.000000    1.000000    0.000000 

I've tried:

sourcetype=infra subtype=system | stats sparkline count, avg(cpu) by devicename
or
sourcetype=infra subtype=system | stats sparkline(avg(cpu)) by devicename

But I don't think that displays the good line chart!
I've also tried:

sourcetype=infra subtype=system | stats sparkline(avg(cpu),1m) by devicename

Could you tell me what is the variable "1m"?
Does it mean "1 month"?

Regards
Chris

0 Karma

chrbar01
Explorer

Thanks cmerriman.

Please, could you tell me if the syntax of my searchs with sparkline are correct, or if another will be better?
I've tried:

sourcetype=infra subtype=system | stats sparkline count, avg(cpu) by devicename
and
sourcetype=infra subtype=system | stats sparkline(avg(cpu)) by devicename
0 Karma

cmerriman
Super Champion

it depends on what you're trying to obtain

sourcetype=infra subtype=system | stats sparkline count, avg(cpu) by devicename

this search will give you a sparkline that shows the count over the timeframe you're specifying for each device

sourcetype=infra subtype=system | stats sparkline(avg(cpu)) by devicename

this search will give you a sparkline that shows the average cpu over the timeframe you're specifying for each device.

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...