Splunk Search

Help with search to draw a timechart for dynamic input

mayank101
New Member

I have a checkbox in which user has to enter the hostname manually by himself.
So on the basis of the hostname entered the time chart for that hostname should be drawn automatically.
I am unable to incorporate this feature. Can anyone help in writing the search?
I am particularly new to Splunk.

0 Karma

lakshman239
Influencer

If you capture the value entered in a field, say hostname, you can do something like your search |eval myhost=$hostname$ | timechart count by myhost

You can change based on what you want to plot in the timechart.

0 Karma

mayank101
New Member

Can you please tell me how to capture the hostname,right now I am just able to enter the hostname in checkbox named filterhost.It still shows waiting for the input and no result is getting displayed.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...