- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
I have a line graph that charts the consumed disk capacity for many hosts. It is very nice for giving a rough idea of the trends, and if I hover over the line at a specific point in time, I can get the capacity value at that time.
How would I be able to make a permanent marker or annotation at obvious points of interest? For instance, a 4% or %5 jump in consumed disk?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/eccc5/eccc547d25d75d39fd22c7eaac96f975e5768ca2" alt="Paolo_Prigione Paolo_Prigione"
Hi muebel, I fear right now it is not possible: the "annotation" charts have not yet been implemented and on the module reference I can see no config for sticking permanent labels.
Moreover "obvious" points of interests should be something you have to help splunk figure out. A workaround could be to timechart something like the following, which might help you spot out potential issues:
| bucket _time span=1h | stats count(_raw) as c by _time,host | delta c as delta p=1 | eval perc_variation = round((delta * 100 / (c - delta)),1) | eval abs_variation=abs(perc_variation) | where abs_variation > 5 | fields host, c, perc_variation
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/eccc5/eccc547d25d75d39fd22c7eaac96f975e5768ca2" alt="Paolo_Prigione Paolo_Prigione"
Hi muebel, I fear right now it is not possible: the "annotation" charts have not yet been implemented and on the module reference I can see no config for sticking permanent labels.
Moreover "obvious" points of interests should be something you have to help splunk figure out. A workaround could be to timechart something like the following, which might help you spot out potential issues:
| bucket _time span=1h | stats count(_raw) as c by _time,host | delta c as delta p=1 | eval perc_variation = round((delta * 100 / (c - delta)),1) | eval abs_variation=abs(perc_variation) | where abs_variation > 5 | fields host, c, perc_variation
data:image/s3,"s3://crabby-images/d7f73/d7f73632dd731f9b3dd280d9d048df61ba67932c" alt=""