Splunk Search

How to change a search query in the Splunk Insights for Infrastructure?

kvaga
Explorer

Currently I have incoming events (from logs). The predefined charts look like histogram of count of events for a specific period. How can I change conditions of search query?

1 Solution

pwu_splunk
Splunk Employee
Splunk Employee

You can change the time-picker in the upper-left corner to change the time range. You can change some parameters of the histogram with the side panel on the right. Outside of that, SII doesn't have further graph customization at this time.

To expand events and explore the log data, click on the button in the upper-right corner.

alt text

View solution in original post

pwu_splunk
Splunk Employee
Splunk Employee

You can change the time-picker in the upper-left corner to change the time range. You can change some parameters of the histogram with the side panel on the right. Outside of that, SII doesn't have further graph customization at this time.

To expand events and explore the log data, click on the button in the upper-right corner.

alt text

kvaga
Explorer

Ok
Thanks
I'll be waiting for the further customizations in the new versions of SII. It would be a usefull feature to create own charts

0 Karma

ntankersley_spl
Splunk Employee
Splunk Employee

What kind of charts are you looking to create? Do you want general access to the SPL query language for customization or would you like this to be a part of the UI?

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...