I have a dashboard that displays a weekly summary of detected signatures, but I would like to be able to show the number of events per signature on the chart. Is this possible?
Current simple XML:
<?xml version='1.0' encoding='utf-8'?>
<dashboard>
<row>
<chart>
<title>AV Detect Report (7 day)</title>
<searchString> MY_SEARCH </searchString>
<earliestTime>-7d</earliestTime>
<latestTime>now</latestTime>
<option name="charting.chart">pie</option>
</chart>
</row>
</dashboard>
Thanks.
So I figured out how to do do this based on a response to another similar question.
my_search | stats count by signature | eval signature_slice = "Events: " + count + ", " + signature | fields signature_slice, count
So I figured out how to do do this based on a response to another similar question.
my_search | stats count by signature | eval signature_slice = "Events: " + count + ", " + signature | fields signature_slice, count
You can show the value of the percent such as:
<?xml version='1.0' encoding='utf-8'?>
<dashboard>
<row>
<chart>
<title>AV Detect Report (7 day)</title>
<searchString> MY_SEARCH </searchString>
<earliestTime>-7d</earliestTime>
<latestTime>now</latestTime>
<option name="charting.chart">pie</option>
<option name="charting.chart.showPercent">true</option>
</chart>
</row>
</dashboard>
In Splunk, you can't without using 3rd party libraries and building your own UI for it.