Splunk Search

How do I add sparkline to the search result for generating a report?

mike7860
Explorer

I need to add a sparkline to the search result so that I can create a visualization of which index is reporting a spike in usage. My serach result is as follows:

earliest=-2d@d latest=-1d@d index=_internal group="per_index_thruput" | eval rmb = round(kb/1024, 2) | eval rgb = round(rmb/1024, 2) | eval mb = kb/1024 | eval gb = round(kb/1024/1024, 2) | stats sum(gb) AS "Total GB" by series | addcoltotals

Tags (1)
0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

It's a charting command, you could place it inline with your other stats command. What stat did you want to show in the sparkline?

earliest=-2d@d latest=-1d@d index=_internal group="per_index_thruput" | eval rmb = round(kb/1024, 2) | eval rgb = round(rmb/1024, 2) | eval mb = kb/1024 | eval gb = round(kb/1024/1024, 2) | stats sparkline sum(gb), sum(gb) AS "Total GB" by series | addcoltotals

http://docs.splunk.com/Documentation/Splunk/5.0/Search/Addsparklinestosearchresults

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...