Dashboards & Visualizations

To create dashboard for win EventIDs

phanikumarcs
Explorer

Hi @ITWhisperer

need help, how many ways to show up in the dashboard where the eventids

index=foo_win*  (host="PC*" EventID=1068) OR (host="PR**" EventID="1") OR (host="PR*" EventID="1") OR (host="PR*" EventID="1").......
where _time, server(host), eventid, severity (warning, critical, info)

Desired to achieve like below snap.

phanikumarcs_0-1709545349110.png

 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

For each panel, what search are you using or going to use?

0 Karma

phanikumarcs
Explorer

@ITWhisperer  i created like this,

phanikumarcs_0-1709550109831.png

in the Event Types

phanikumarcs_1-1709550169832.png

 

phanikumarcs_2-1709550206426.png

 

index=foo_win*  (host="PC*" EventID=1068) OR (host="PR**" EventID="1") OR (host="PR*" EventID="1") OR (host="PR*" EventID="1")
| eval Severity=case(EventID="1068", "Warning",
EventID="1", "Information",
EventID="1021", "Warning")
| stats count by Severity

writing above spl under all three pannels(critical, warning,information)

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

OK so it is not clear what you are asking for. Please can you expand on your usecase and the issue(s) you are facing?

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...