Splunk Search

How to create a visualization for different event structures?

donaldwayne1975
Path Finder

Have events that have 10+ variables in each. I want to be able to show correlations for one seed value and 1 to 10+ other variables grouped. Example graphic is below.

Example scenario would be buying a car. There are lots of options that a vehicle can have added. Like All-wheel drive (if needed or plan to drive in snow/off road areas), Aluminum alloy wheels (no wheel covers), Ambient/outside temperature display, Auto-dimming rear and power folding side view mirrors, Automatic headlights, Bi-Xenon/HID headlights (high and low beam), Blind spot and cross path detection, Cruise control – adaptive if available, Convertible top – fully-automatic operation, Cup holders – heated and cooled, Digital compass, and color.

Let's say I want the color to be the seed variable and want to see correlations on the 4 other variables of Automatic headlights, All-wheel drive (if needed or plan to drive in snow/off road areas), Convertible top – fully-automatic operation, and Cup holders – heated and cooled.
alt text

0 Karma
1 Solution

niketn
Legend

You might have to include either Force Directed Graph or D3 Hive Plot. Refer to D3 Force-Directed Graph: Splunkweb view navigation example in Splunk 6.x Dashboard Examples.
Also refer to the link http://docs.splunk.com/Documentation/Splunk/6.5.1/AdvancedDev/CustomVizTutorial for creating your own Custom Visualization if you are interested in D3 Hive Plot.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

niketn
Legend

You might have to include either Force Directed Graph or D3 Hive Plot. Refer to D3 Force-Directed Graph: Splunkweb view navigation example in Splunk 6.x Dashboard Examples.
Also refer to the link http://docs.splunk.com/Documentation/Splunk/6.5.1/AdvancedDev/CustomVizTutorial for creating your own Custom Visualization if you are interested in D3 Hive Plot.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...