Splunk Search

How to create a visualization for different event structures?

donaldwayne1975
Path Finder

Have events that have 10+ variables in each. I want to be able to show correlations for one seed value and 1 to 10+ other variables grouped. Example graphic is below.

Example scenario would be buying a car. There are lots of options that a vehicle can have added. Like All-wheel drive (if needed or plan to drive in snow/off road areas), Aluminum alloy wheels (no wheel covers), Ambient/outside temperature display, Auto-dimming rear and power folding side view mirrors, Automatic headlights, Bi-Xenon/HID headlights (high and low beam), Blind spot and cross path detection, Cruise control – adaptive if available, Convertible top – fully-automatic operation, Cup holders – heated and cooled, Digital compass, and color.

Let's say I want the color to be the seed variable and want to see correlations on the 4 other variables of Automatic headlights, All-wheel drive (if needed or plan to drive in snow/off road areas), Convertible top – fully-automatic operation, and Cup holders – heated and cooled.
alt text

0 Karma
1 Solution

niketn
Legend

You might have to include either Force Directed Graph or D3 Hive Plot. Refer to D3 Force-Directed Graph: Splunkweb view navigation example in Splunk 6.x Dashboard Examples.
Also refer to the link http://docs.splunk.com/Documentation/Splunk/6.5.1/AdvancedDev/CustomVizTutorial for creating your own Custom Visualization if you are interested in D3 Hive Plot.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

niketn
Legend

You might have to include either Force Directed Graph or D3 Hive Plot. Refer to D3 Force-Directed Graph: Splunkweb view navigation example in Splunk 6.x Dashboard Examples.
Also refer to the link http://docs.splunk.com/Documentation/Splunk/6.5.1/AdvancedDev/CustomVizTutorial for creating your own Custom Visualization if you are interested in D3 Hive Plot.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...