Splunk Search

Help with Dashboarding

aag
Engager

Hello,

Here is the whole context and question:

https://community.splunk.com/t5/Splunk-Search/Aggregate-query-help/m-p/560663/highlight/true#M159340

As a next step from the search query would like to showcase the result on dashboard, where from a drop down when we select a particular attribute it will show the count of total and RecordOutRange on y-axis in time span of every15min on x-axis.

Thanks,

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Create the dropdown so that the label is the description of the attribute you want to choose and the value to be the search condition for that attribute, then use the token in the search of the dashboard.

<choice value="count(eval(number < idx1 OR number > idx2)) as RecordOutRange by attr">Attribute</choice>

You might need to encode the < and >

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...