Dashboards & Visualizations

To create dashboard for win EventIDs

phanikumarcs
Explorer

Hi @ITWhisperer

need help, how many ways to show up in the dashboard where the eventids

index=foo_win*  (host="PC*" EventID=1068) OR (host="PR**" EventID="1") OR (host="PR*" EventID="1") OR (host="PR*" EventID="1").......
where _time, server(host), eventid, severity (warning, critical, info)

Desired to achieve like below snap.

phanikumarcs_0-1709545349110.png

 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

For each panel, what search are you using or going to use?

0 Karma

phanikumarcs
Explorer

@ITWhisperer  i created like this,

phanikumarcs_0-1709550109831.png

in the Event Types

phanikumarcs_1-1709550169832.png

 

phanikumarcs_2-1709550206426.png

 

index=foo_win*  (host="PC*" EventID=1068) OR (host="PR**" EventID="1") OR (host="PR*" EventID="1") OR (host="PR*" EventID="1")
| eval Severity=case(EventID="1068", "Warning",
EventID="1", "Information",
EventID="1021", "Warning")
| stats count by Severity

writing above spl under all three pannels(critical, warning,information)

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

OK so it is not clear what you are asking for. Please can you expand on your usecase and the issue(s) you are facing?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...