Dashboards & Visualizations

Visual Dashboard using 4 fields in Stats count

jeish99
Engager

I'm trying to create a visual dashboard  (specifically a column graph or bar chart) using 

index=guardium ruleDesc="OS Command Injection"
| stats count by dbUser, DBName, serviceName, sql

 

This is the graph I get:

Screenshot (47).png

I would like to group these fields into categories on the chart where one part would show count of 1-5 then 6-10...and so on.  Then I could drill down a specific bar within the count group to view the fields for that bar in a table format.  How would I go about doing this.  I am new to splunk and have been stuck finding the best way to represent this data.  I was given this search statement and was told to make a visual dashboard of it.

Labels (2)
0 Karma
1 Solution

fredclown
Builder

You would do a second stats to roll them up like this ...

index=guardium ruleDesc="OS Command Injection"
| stats count by dbUser, DBName, serviceName, sql
| eval category = case(
    count < 6, "1-5",
    count < 11, "6-10",
    count < 16, "11-15",
    1==1, "16+"
)
| stats count by category

Then you would set up a drilldown on the chart to pass a token to another search and limit it based on the token..

View solution in original post

0 Karma

fredclown
Builder

You would do a second stats to roll them up like this ...

index=guardium ruleDesc="OS Command Injection"
| stats count by dbUser, DBName, serviceName, sql
| eval category = case(
    count < 6, "1-5",
    count < 11, "6-10",
    count < 16, "11-15",
    1==1, "16+"
)
| stats count by category

Then you would set up a drilldown on the chart to pass a token to another search and limit it based on the token..

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...