Splunk Search

How to change a search query in the Splunk Insights for Infrastructure?

kvaga
Explorer

Currently I have incoming events (from logs). The predefined charts look like histogram of count of events for a specific period. How can I change conditions of search query?

1 Solution

pwu_splunk
Splunk Employee
Splunk Employee

You can change the time-picker in the upper-left corner to change the time range. You can change some parameters of the histogram with the side panel on the right. Outside of that, SII doesn't have further graph customization at this time.

To expand events and explore the log data, click on the button in the upper-right corner.

alt text

View solution in original post

pwu_splunk
Splunk Employee
Splunk Employee

You can change the time-picker in the upper-left corner to change the time range. You can change some parameters of the histogram with the side panel on the right. Outside of that, SII doesn't have further graph customization at this time.

To expand events and explore the log data, click on the button in the upper-right corner.

alt text

kvaga
Explorer

Ok
Thanks
I'll be waiting for the further customizations in the new versions of SII. It would be a usefull feature to create own charts

0 Karma

ntankersley_spl
Splunk Employee
Splunk Employee

What kind of charts are you looking to create? Do you want general access to the SPL query language for customization or would you like this to be a part of the UI?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...