Dashboards & Visualizations

i need to inputs values of fields in dashboard using tstats

rahul_mckc_splu
Loves-to-Learn

I have datamodel as AWS and have 2 datasets 1.config and 2. cloud-trail ...
Below is the query which i am using in dashboard to get desired information where i am passing fields but it is not working

|tstats summariesonly=T from datamodel=AWS.config where config.configuration.instanceId=$field1$ OR config.configuration.networkInterfaceId=$field1$ OR config.configuration.groupId=$field1$ OR config.configuration.vpcId==$field1$ by config.aws_account_id | table config.configuration.instanceId config.configuration.networkInterfaceId config.configuration.groupId config.configuration.vpcId

Tags (1)
0 Karma

rahul_mckc_splu
Loves-to-Learn

Yes it is accelerated

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Is the datamodel accelerated and has acceleration completed? If either answer is 'no' then tstats will fail because summariesonly=T is specified.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

Unlock Instant Security Insights from Amazon S3 with Splunk Cloud — Try Federated ...

Availability: Must be on Splunk Cloud Platform version 10.1.2507.x to view the free trial banner. If you are ...