Dashboards & Visualizations

To create dashboard for win EventIDs

phanikumarcs
Explorer

Hi @ITWhisperer

need help, how many ways to show up in the dashboard where the eventids

index=foo_win*  (host="PC*" EventID=1068) OR (host="PR**" EventID="1") OR (host="PR*" EventID="1") OR (host="PR*" EventID="1").......
where _time, server(host), eventid, severity (warning, critical, info)

Desired to achieve like below snap.

phanikumarcs_0-1709545349110.png

 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

For each panel, what search are you using or going to use?

0 Karma

phanikumarcs
Explorer

@ITWhisperer  i created like this,

phanikumarcs_0-1709550109831.png

in the Event Types

phanikumarcs_1-1709550169832.png

 

phanikumarcs_2-1709550206426.png

 

index=foo_win*  (host="PC*" EventID=1068) OR (host="PR**" EventID="1") OR (host="PR*" EventID="1") OR (host="PR*" EventID="1")
| eval Severity=case(EventID="1068", "Warning",
EventID="1", "Information",
EventID="1021", "Warning")
| stats count by Severity

writing above spl under all three pannels(critical, warning,information)

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

OK so it is not clear what you are asking for. Please can you expand on your usecase and the issue(s) you are facing?

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...