Dashboards & Visualizations

Need to get JOB.ID per instance per dashboard

robertlynch2020
Influencer

Hi

I have a list of all the ID RUNNING per dashboard (But if someone else is running the same dashboard i get those ID's as well, how can i reduce it down? ) I run this SPL from the dashboard i want to reduce it down to.

In this case the Dashboard is kpi_monitoring_robbie.

| rest /services/search/jobs | search dispatchState="RUNNING"  AND provenance="*kpi_monitoring_robbie*" 
| fields id provenance dispatchState

OUTPUT

id  provenance  dispatchState
https://127.0.0.1:8089/services/search/jobs/admin__admin__Murex__search60_1581445194.220651 UI:Dashboard:kpi_monitoring_robbie  RUNNING
https://127.0.0.1:8089/services/search/jobs/admin__admin__Murex__search61_1581445194.220652 UI:Dashboard:kpi_monitoring_robbie  RUNNING
https://127.0.0.1:8089/services/search/jobs/admin__admin__Murex__search63_1581445194.220654 UI:Dashboard:kpi_monitoring_robbie  RUNNING

But one of the above was from the second dashboard.
I cant do it per user as a lot of user have the same user name, if i was using LDAP i could.

Thanks in Advance
Robert

Tags (1)
0 Karma

codebuilder
Influencer

Try this (or adjust it to your needs):

| rest /services/search/jobs 
| cluster field=provenance showcount=t
| search dispatchState="RUNNING" AND provenance="kpi_monitoring_robbie"
| table cluster_count id dispatchState provenance

My example uses asterisks, just to get some data, but you get the idea.
alt text

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

robertlynch2020
Influencer

Thank for this, but i need to be able to get this per dashboards instance, not just per dashboard.

So i need a way to tell users at the end of a dashboard that there dashboard is 100% loaded.

However if i cluster i could have 2 separate people running the same dashboard it will group them together.

Cheers
Rob

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...