Splunk Search

Annotation based on Existing Value (to avoid duplicate search)

lennys26
Communicator

On an existing dashboard I have a rather complex query that generates a timechart on which I am looking to use annotations to highlight threshold breaches.

Is there any way to avoid having to run the same query twice (once to create the initial chart, and a second time for the annotations).

Oh -- [I think I have may be answering my own question,] is the answer here going to be to use a base search?

Thanks.

 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, a base search will be a good start.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Yes, a base search will be a good start.

---
If this reply helps you, Karma would be appreciated.

lennys26
Communicator

@richgalloway  - Thanks. I tend to shy away from base searches for some reason.

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...