Splunk Search

Adding multiple sparklines in a search

theouhuios
Motivator

I am trying to add multiple sparklines to a search. When I use this

stats sparkline avg(ProcV) as ProcV  sparkline avg(DiskV) as DiskV  sparkline avg(ProcQueue) as ProcQueue avg(DiskQueue) as DiskQueue avg(ByteT) as ByteT avg(Curcon) as Curcon avg(RWT) as RWT

it only shows sparkline for avg(ProcV) but ignoring others. Thats the same when I use chart.

So I am trying to append the data to the present search results, instead of placing the sparklines for those 3 counters beside the hosts, it creates another set of host fields and then places the saprklines.

| stats avg(ProcV) as ProcV  avg(DiskV) as DiskV   avg(ProcQueue) as ProcQueue avg(DiskQueue) as DiskQueue avg(ByteT) as ByteT avg(Curcon) as Curcon avg(RWT) as RWT
avg(ASP) as ASP avg(ASPv2) as ASPv2 avg(ASPv4) as ASPv4 by host|append [search earliest=-30m@m latest=@m  sourcetype="Perfmon:*" serverType= "B2C WEB APP" counter="% Processor Time" OR counter="Available Kbytes" OR counter="Current Connections"|eventstats avg(Value) as AvgValue by host counter |chart sparkline avg(AvgValue) over host by counter | fields - avg(AvgValue)*|sort - host]

Here is the image on what it does

alt text

Tags (1)
0 Karma

jonuwz
Influencer

Try :

stats sparkline(avg(ProcV)) as ProcV  sparkline(avg(DiskV)) as DiskV  sparkline)avg(ProcQueue)) as ProcQueue avg(DiskQueue) as DiskQueue avg(ByteT) as ByteT avg(Curcon) as Curcon avg(RWT) as RWT by host
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Splunk Observability Metrics Cost Optimization

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...