Dashboards & Visualizations

Sparkline not working in 7.2.6

robertlynch2020
Influencer

Hi

I am on version 7.1.6 and want to move to 7.2.6 but i have noticed that spark-lines don't work in the new version.

Or am i missing something?

This is the SPL

index=mlc_live  | table host  _time| chart sparkline count by host | fields - count

When i change from fast mode to verbose mode in SPL it works, but you cant save a search that way.

Any help would be great.

1 Solution

burwell
SplunkTrust
SplunkTrust

Hi. I did a quick test on my Mac with 7.2.6 and I see the bug as well.

I opened a case with Splunk. I will post results here.

I also discovered it is the order of the arguments. For example the following DOES work in 7.2.6

index=_internal  | chart count
  sparkline by sourcetype  | sort -count

View solution in original post

0 Karma

jberwick_splunk
Splunk Employee
Splunk Employee

I would try using stats/chart command first then table the results.

index=_internal | stats sparkline count by host | table host sparkline count

0 Karma

niketn
Legend

I tried the following run anywhere example in Windows machine with 7.2.6 on chrome, edge, IE and Firefox browsers and it worked fine.

alt text

<dashboard>
  <label>Sparkline</label>
  <row>
    <panel>
      <table>
        <search>
          <query>index=_internal 
| chart sparkline count by sourcetype
| fields - count</query>
          <earliest>-24h@h</earliest>
          <latest>now</latest>
          <sampleRatio>1</sampleRatio>
        </search>
        <option name="count">20</option>
        <option name="dataOverlayMode">none</option>
        <option name="drilldown">none</option>
        <option name="percentagesRow">false</option>
        <option name="refresh.display">progressbar</option>
        <option name="rowNumbers">false</option>
        <option name="totalsRow">false</option>
        <option name="wrap">true</option>
      </table>
    </panel>
  </row>
</dashboard>
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

burwell
SplunkTrust
SplunkTrust

Which mode did you test in?

0 Karma

niketn
Legend

Since this is dashboard it will not need search mode. However, I did test test with Fast Mode as well.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

burwell
SplunkTrust
SplunkTrust

Hi. I did a quick test on my Mac with 7.2.6 and I see the bug as well.

I opened a case with Splunk. I will post results here.

I also discovered it is the order of the arguments. For example the following DOES work in 7.2.6

index=_internal  | chart count
  sparkline by sourcetype  | sort -count
0 Karma

burwell
SplunkTrust
SplunkTrust

@robertlynch2020 try just removing the table line in your query.

I think your sparkline will work in all modes then.

robertlynch2020
Influencer

Hi

From one Splunk Ninja(2017) to another(2018) - thanks very much 🙂

0 Karma

AKG1_old1
Builder

@burwell : removing table command worked !! cheers!

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...