Dashboards & Visualizations

How would I display the number of events on a pie chart?

digital_alchemy
Path Finder

I have a dashboard that displays a weekly summary of detected signatures, but I would like to be able to show the number of events per signature on the chart. Is this possible?

Current simple XML:

<?xml version='1.0' encoding='utf-8'?>
<dashboard>
<row>
<chart>
<title>AV Detect Report (7 day)</title>
<searchString> MY_SEARCH </searchString>
<earliestTime>-7d</earliestTime>
<latestTime>now</latestTime>
<option name="charting.chart">pie</option>
</chart>
</row>
</dashboard>

Thanks.

0 Karma
1 Solution

digital_alchemy
Path Finder

So I figured out how to do do this based on a response to another similar question.

my_search | stats count by signature | eval signature_slice = "Events: " + count + ", " + signature | fields signature_slice, count

View solution in original post

digital_alchemy
Path Finder

So I figured out how to do do this based on a response to another similar question.

my_search | stats count by signature | eval signature_slice = "Events: " + count + ", " + signature | fields signature_slice, count

dmaislin_splunk
Splunk Employee
Splunk Employee

You can show the value of the percent such as:

<?xml version='1.0' encoding='utf-8'?>
<dashboard>
    <row>
        <chart>
            <title>AV Detect Report (7 day)</title>
            <searchString> MY_SEARCH </searchString>
           <earliestTime>-7d</earliestTime>
           <latestTime>now</latestTime>
            <option name="charting.chart">pie</option>
            <option name="charting.chart.showPercent">true</option>
        </chart> 
     </row>
</dashboard>

jtrucks
Splunk Employee
Splunk Employee

In Splunk, you can't without using 3rd party libraries and building your own UI for it.

--
Jesse Trucks
Minister of Magic
0 Karma
Get Updates on the Splunk Community!

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...