Dashboards & Visualizations

Realtime dashboard

Nith1
Path Finder

Hi Team,

 

I have my logs for jira,bamboo and ucd in splunk with indexes like index=jira,index=bamboo and index=ucd for all these tools need to build a realtime dashboard .Can someone guide me how to show as a realtime dashboard

 

Thanks

 

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Nith1,

you have to run one by one the searches in your indexes (e.g. index=jira), applying  each time the aggregations you like (stats, timechart, table, etc...), then you have to save each search in a different panel of a dashboard.

Then you have to add a Time Picker and correlate each panel to the Time Picker.

You could find and see in YouTube some videos that teach how to do this.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Nith1,

you have to run one by one the searches in your indexes (e.g. index=jira), applying  each time the aggregations you like (stats, timechart, table, etc...), then you have to save each search in a different panel of a dashboard.

Then you have to add a Time Picker and correlate each panel to the Time Picker.

You could find and see in YouTube some videos that teach how to do this.

Ciao.

Giuseppe

Nith1
Path Finder

Hi @gcusello 

One more doubt please, whenever i do some modification in jira (eg:, i create an issue ) can i view the same in splunk dashboard at the sametime. I mean can i get a Realtime view for the same

 

Thanks

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nith1,

if your Jira logs all the steps you do in it, the log is passed to Splunk.

If it's really in Real Time depends on the time to pass data from Jira to Splunk.

I don't know your need, but remember that a Real Time search like the one you described is very expensive in terms of resources, because each search in Splunk takes a CPU, so if you have a dashboard with three Real Time Searches, each dashboard continously uses three CPUs, so you have to correctly make a Capacity Plan for you infrastructure.

Otherwise you should analyze if you really need Real Time Searches or if you can run a search that updates results e.g. every five minutes.

Ciao.

Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...