I have repeated failed logins listed as "Other" in my pie chart for Failed Logins by Host. How can I find out what those "other" devices or hostnames are? There were 85 Other in Failed logins by host and 9 Other in the successful logins by host. I need help determining what "Other" means in this context.
"Other" means there are too many entries (more than 10 by default) for the chart command to display. You should be able to click on the "Other" wedge to drill down and find out which hosts they are. If clicking doesn't work, add a Drilldown in the dashboard panel.
When I click on the Other wedge, it displays the search window and I click the magnifying glass but nothing is displayed (says No results found). How do you add a drilldown on the dashboard? I am really new to splunk. So my questions are for a novice user.
To add a drilldown to a dashboard, first click the "Edit" button in the top-right corner of the dashboard. If the button is not there then you will need CLI access to edit the dashboard code.
In the panel containing the pie chart, click on the triple-dot icon and select "Edit Drilldown". Select "Link to search" from the dropdown then choose "Custom". It "Search String" box should populate with the search from the panel. Modify the query to produce the desired output and then click Apply. Click Save at the top-right to commit the dashboard changes.