Splunk Search

How to write a search that groups values to be used in a dropdown on a dashboard?

quietferret
Loves-to-Learn

Hi All,

I am new to Splunk and the SPL in general so I will try and explain as best I can.  I have been tasked to produce an UP/DOWN dashboard to show different Microsoft Cloud services and their statuses.  We are importing data from the Microsoft Service Health and can run searches on it.  I am able to find each service (Microsoft Teams, Exchange Online, SharePoint Online etc) and their current status (up or down). 

Now I need to show this in a dashboard but my manager wants to group the services in categories like, Core services, Productivity and Cloud Apps so that if a person navigates tot he dashboard they can click a dropdown and select the category then those services are displayed  with their UP/DOWN status.  

Any help would be much appreciated.

Labels (4)
0 Karma

quietferret
Loves-to-Learn

Ok so I had the following:

index=azure source="ServiceAnnouncement.Issues" | sort 0 - _time | eval category = if(service = "Exchange Online" , "Core Service" , other)

But how can I do multiple if statements?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You probably need to eval a new field which categorises the services and then filter on those categories. You could use a case function or if functions to do the evaluation, or you could define and use a lookup to map the service to its category.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...