Dashboards & Visualizations

Make a graph displaying enabled/disabled status of a process

tbrown
Path Finder

I have logs coming in that are the following: 

 

 

State change from '0' to '1' is complete

 

 

or

 

 

State change from '1' to '0' is complete

 

 

 on multiple nodes. 

Basically, I want a graph/visualization that displays the most recent status of the hosts. I've used | rex field to extract the value either '0/1' on each log after "to" but I'm wondering how I could do it so that the graph shows the most recent state of each node, maybe a bar graph or something where a green bar=1 and a red bar=0, separated by hosts.,

Any advice is appreciated, thanks!

Labels (4)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

See if this helps.

index=foo
| rex "from \d to (?<state>\d)"
| stats latest(state) by host
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

See if this helps.

index=foo
| rex "from \d to (?<state>\d)"
| stats latest(state) by host
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...