Dashboards & Visualizations

Key indicator question

matt1t
Explorer

I created a key indicator and when I click the preview button I get the results I want:alt text

However, when I add this to my dashboard it will not show the results, any idea why?

Here is what my dashboard shows.
alt text

Tags (2)
0 Karma
1 Solution

matt1t
Explorer

I figured it out, however this makes no sense. Many examples on the key indicators start with search and then the actual search. Example would be "search index=some_index earliest=-3d@d blah blah blah". With the search in front my preview works, but the results are missing on the dashboard. If I take the search out of it, the preview no longer work, however its now working on my dashboard. I don't know what made me try that but I now have my dashboard working so I'm happy. Maybe someone can explain the difference?

Thanks,

-Matt

View solution in original post

0 Karma

matt1t
Explorer

I figured it out, however this makes no sense. Many examples on the key indicators start with search and then the actual search. Example would be "search index=some_index earliest=-3d@d blah blah blah". With the search in front my preview works, but the results are missing on the dashboard. If I take the search out of it, the preview no longer work, however its now working on my dashboard. I don't know what made me try that but I now have my dashboard working so I'm happy. Maybe someone can explain the difference?

Thanks,

-Matt

0 Karma

niketn
Legend

@matt1t once the search query runs, how are you moving the panel to your dashboard? Are you using Save as Dashboard option or are you merging the search <query> manually? By any chance are you using Post-Processing in the dashboard?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

matt1t
Explorer

I wonder is this is the issue. So when I click on the preview, my search runs and I get the data I expect. If I'm within the Content Management section and look at the info for my key indicator I get the following stats:

Statistics
Avg. Event Count ..... 17.36
Avg. Result Count ..... 0
Avg. Run Time ....... 0:00:02
Invocations ....... 25
Skipped ........ 0
Success ........0
Update Time ........ Jan 6, 2020 10:30:00 AM

So no successes and 25 invocations? What are invocations and how can I fix this?

0 Karma

matt1t
Explorer

On the dashboard I click edit, and then it has a plus sign which then loads a Add Indicators. I choose the indicator I created and then its added.

0 Karma
Get Updates on the Splunk Community!

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...

Hunt Smarter, Not Harder: Discover New SPL “Recipes” in Our Threat Hunting Webinar

Are you ready to take your threat hunting skills to the next level? As Splunk community members, you know the ...