Dashboards & Visualizations

Pie-chart - Display TOTAL in title of the pie-chart but hide/block from displaying in pie-chart

index=$index$ sourcetype=$sourcetype$ $string1$
| fillnull value=FALSE
| stats 
count(email) AS TOTAL 
count(eval(authenticated="TRUE")) AS auth_count 
count(eval(cancelled="TRUE")) AS cancelled_count  
count(eval(promoted="TRUE")) AS PROVISIONED 
| eval AUTH_DROP_OUT=TOTAL-auth_count
| eval USER_CANCELLED=auth_count-cancelled_count
| transpose
| rename column AS ActionTaken "row "1 AS Count
| eval ActionTaken=ActionTaken." : ".Count
0 Karma



For total in Pie Chart Label, can you please try this?

  <label>Test Dashboard</label>
  <search base="mysearch">
    <query>stats sum(count) as total</query>
      <set token="total">$result.total$</set>
      <title>My Pie Chart $total$</title>
        <search id="mysearch">
| stats count by log_level</query>
        <option name="count">20</option>
        <option name="dataOverlayMode">none</option>
        <option name="drilldown">none</option>
        <option name="percentagesRow">false</option>
        <option name="refresh.display">progressbar</option>
        <option name="rowNumbers">false</option>
        <option name="totalsRow">false</option>
        <option name="wrap">true</option>
0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...