Splunk Search

How to edit my search to get the output to show on a radial gauge?

TJ0214
New Member

I am trying to show the total amount of space we are using in a box right now for a dashboard. Here is my following serach, but I can't get the output to show on the needle. I was hoping it would work. Any ideas?

index=es_sec_box_ko sourcetype="box:users" | eval spaceUsed_GB=(space_used/1024/1024/1024) | where spaceUsed_GB >0 |stats latest(spaceUsed_GB) as spaceUsed_GB count by login |addcoltotals | sort -spaceUsed_GB

Thanks!

0 Karma

somesoni2
Revered Legend

Try something like this (little optimization done as well)

index=es_sec_box_ko sourcetype="box:users" space_used>0 |stats latest(space_used) as space_used by login  | eval spaceUsed_GB=(space_used/1024/1024/1024)| stats sum(spaceUsed_GB) as spaceUsed_GB
0 Karma

woodcock
Esteemed Legend

Try this:

index=es_sec_box_ko sourcetype="box:users" | dedup login | eval spaceUsed_GB=(space_used/1024/1024/1024) | stats sum(spaceUsed_GB) as total_spaceUsed_GB

This will produce a single value that should display in your single-value visualization.

0 Karma

woodcock
Esteemed Legend

What do you mean by "show on the needle"? If you mean some kind of single-value visualization, then you need to get rid of the by login part of your search because this causes stats to not produce a single value.

0 Karma

TJ0214
New Member

Im sorry I meant the radial gauge for a dashboard option does that help?

0 Karma

TJ0214
New Member

I took out by login and got no data.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...