Dashboards & Visualizations

Why is health dashboard help showing if an even was received in the last x minutes?

Keo
Loves-to-Learn

Hi all.  I am very new to splunk so please be gentle here. 🙂

I have the following json payload being updated in our splunk index.

 

 

{
  "status": "open",
  "description": "some information here"
  "severity": "unknown",
  "ingestion_source": "source type here"
}

 

 

 

What I want to do is have a tile that is per ingestion_source that turns red if a new payload hasn't been received in the last 5 minutes.

I know how to make the query, I am just struggling with how to make the dashboard do what I explained.

Any help is much appreciated.

Labels (2)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...

SplunkTrust | 2024 SplunkTrust Application Period is Open!

It's that time again, folks! That's right, the application/nomination period for the 2024 SplunkTrust is ...