Splunk Search

Help with Dashboarding

aag
Engager

Hello,

Here is the whole context and question:

https://community.splunk.com/t5/Splunk-Search/Aggregate-query-help/m-p/560663/highlight/true#M159340

As a next step from the search query would like to showcase the result on dashboard, where from a drop down when we select a particular attribute it will show the count of total and RecordOutRange on y-axis in time span of every15min on x-axis.

Thanks,

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Create the dropdown so that the label is the description of the attribute you want to choose and the value to be the search condition for that attribute, then use the token in the search of the dashboard.

<choice value="count(eval(number < idx1 OR number > idx2)) as RecordOutRange by attr">Attribute</choice>

You might need to encode the < and >

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...