Getting Data In

Rangemap on multiple fields? Is it possible?

edenzler
Path Finder

Hi,

I have the following in a table that I'd like to do a rangemap on for each - same ranges, just want to do it all at once.

6/23 6/30 7/7 7/21 7/28 8/4 8/11 8/18 8/25 9/1 9/8 9/15 9/22 9/29 10/6 10/13 10/20 10/27 11/3 11/10 11/17 11/24 12/1 12/8 12/15 12/22

Green = between 32 and 44

Yellow = over 44

Red = less than 32

Any way to do this? Tried wildcarding the rangemap field= star/star "star/star" (asterisk does not work during the post)

Any help would greatly appreciated.

Cheers

0 Karma

asimagu
Builder

what you are doing in a rangemap command is an eval of the field range. The field range is present by default in all the dashboards, so it is only a matter of setting it up in your search and then referring to it on every single value of your dashboard

0 Karma

asimagu
Builder
0 Karma

edenzler
Path Finder

I'm not understanding your answer. How about an SPL example? Thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...