Dashboards & Visualizations

Sparkline not working in 7.2.6

robertlynch2020
Influencer

Hi

I am on version 7.1.6 and want to move to 7.2.6 but i have noticed that spark-lines don't work in the new version.

Or am i missing something?

This is the SPL

index=mlc_live  | table host  _time| chart sparkline count by host | fields - count

When i change from fast mode to verbose mode in SPL it works, but you cant save a search that way.

Any help would be great.

1 Solution

burwell
SplunkTrust
SplunkTrust

Hi. I did a quick test on my Mac with 7.2.6 and I see the bug as well.

I opened a case with Splunk. I will post results here.

I also discovered it is the order of the arguments. For example the following DOES work in 7.2.6

index=_internal  | chart count
  sparkline by sourcetype  | sort -count

View solution in original post

0 Karma

jberwick_splunk
Splunk Employee
Splunk Employee

I would try using stats/chart command first then table the results.

index=_internal | stats sparkline count by host | table host sparkline count

0 Karma

niketn
Legend

I tried the following run anywhere example in Windows machine with 7.2.6 on chrome, edge, IE and Firefox browsers and it worked fine.

alt text

<dashboard>
  <label>Sparkline</label>
  <row>
    <panel>
      <table>
        <search>
          <query>index=_internal 
| chart sparkline count by sourcetype
| fields - count</query>
          <earliest>-24h@h</earliest>
          <latest>now</latest>
          <sampleRatio>1</sampleRatio>
        </search>
        <option name="count">20</option>
        <option name="dataOverlayMode">none</option>
        <option name="drilldown">none</option>
        <option name="percentagesRow">false</option>
        <option name="refresh.display">progressbar</option>
        <option name="rowNumbers">false</option>
        <option name="totalsRow">false</option>
        <option name="wrap">true</option>
      </table>
    </panel>
  </row>
</dashboard>
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

burwell
SplunkTrust
SplunkTrust

Which mode did you test in?

0 Karma

niketn
Legend

Since this is dashboard it will not need search mode. However, I did test test with Fast Mode as well.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

burwell
SplunkTrust
SplunkTrust

Hi. I did a quick test on my Mac with 7.2.6 and I see the bug as well.

I opened a case with Splunk. I will post results here.

I also discovered it is the order of the arguments. For example the following DOES work in 7.2.6

index=_internal  | chart count
  sparkline by sourcetype  | sort -count
0 Karma

burwell
SplunkTrust
SplunkTrust

@robertlynch2020 try just removing the table line in your query.

I think your sparkline will work in all modes then.

robertlynch2020
Influencer

Hi

From one Splunk Ninja(2017) to another(2018) - thanks very much 🙂

0 Karma

AKG1_old1
Builder

@burwell : removing table command worked !! cheers!

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...