Dashboards & Visualizations

replacing host values in a chart

a212830
Champion

Hi,

I have a chart that works, but mgmt wants the host values to map to something more meaningful. Is there a way to do this?

My search is this:

index=coreops sourcetype=snmpinfo source="/usr/local/nsmutils/varlog/splunk_cgk_sessions.log" | head 9 | chart sum(CONNECTIONS) as CONNECTIONS by HOST | eval H=HOST | eval HOST="" | xyseries HOST H CONNECTIONS

Tags (2)
0 Karma
1 Solution

bigtyma
Communicator

You might consider doing a lookup on HOST?

View solution in original post

bigtyma
Communicator

You might consider doing a lookup on HOST?

a212830
Champion

lookup worked. The customer didn't like the name of the hosts, so we mapped it via a lookup.

0 Karma

Ayn
Legend

Well how would you define "useful" in your scenario?

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...