- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Adding Sparkline based on eval variable

I have a search which captures data from all the machines on the network and calculates OS Health of each machine (host). I am displaying it like this
OSHealth DeviceCount Percentage
5 288 35%
4 150 20%
I want to add a sparkline to show the trend of changing percentage and add it like another column. I have tried alot based on splunk docs but it always show as a straight line. I would really appreciate some help. My search is attached below
| stats count(host) AS DeviceCount by OSHealth
| eventstats sum(DeviceCount) AS SumDevice
| eval Percentage = round((DeviceCount/SumDevice)*100,1)
| stats sparkline avg(Percentage) as Trend by OSHealth DeviceCount
| table OSHealth DeviceCount Percentage
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Sparklines require _time to work. However, the initial stats
command is returning only the DeviceCount and OSHealth fields.
If this reply helps you, Karma would be appreciated.
