Splunk Search

How do I display text in a dashboard panel based on the event coverage percentage in its corresponding pivot?

splunkwiz
New Member

I want to display text in the middle of the panel that is based on the value of a status code or its percentage.

I've seen

https://answers.splunk.com/answers/522255/how-to-display-text-message-in-the-center-of-a-das.html?ut...

but I'm not sure what token I would use in my case.

I currently use eval and fields commands in my search, similar to

https://answers.splunk.com/answers/525122/how-to-display-data-value-in-percentage.html?utm_source=ty....

When I do it this way my new dashboard panel is based off a direct search. I also need the % after the number, so currently I've stuck the % as a unit to display.

However, I'd like to use the event coverage percentage. My current dashboard panel is based off a pivot. When I open this in a search, under events, I can click the status code field on the left and it displays the value, count, and %. How do I display this percentage in my panel per each value? How do I display the percentage based on 100% or the value (200 status code)?

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...