Splunk Search

Question on transformation commands

prettysunshinez
Explorer

Hi All,

I need your helping in writing post process & base searches..
My dashboard requires a chart command in the first panel..
So having the post process search as below in first panel,I'm unable to write the base searches in the following panels which requires stats,table and sometimes raw data in them..

1st panel :
Search id = "base"

Query - index = source= | regex field1 | regex field2 | chart count over field1 by field2

2nd panel:
I wanted to perform stats count by field 1

3rd panel :
I want to display the raw events for the select value of field1 from the above panel

4th panel :
I want to display stats count by field x

Please suggest me how can i proceed with it.
Will i be able to use streamstats or eventstats in the first panel or is there any other suggestions for this.

Thanks in advance.

0 Karma

prettysunshinez
Explorer

Any suggestions pls

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Make panel 3 your base search using index = source= | regex field1 | regex field2. The other panels reference the base search and add their respective transformations.

---
If this reply helps you, Karma would be appreciated.
0 Karma

prettysunshinez
Explorer

@richgalloway I would not be able to do that because panel 3 query carries a token of field1 value from Panel 2(cell drilldown)

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Create your base search before the first panel (not in a row). Be aware that this type of base search has limitations. See https://docs.splunk.com/Documentation/Splunk/8.0.3/Viz/Savedsearches#Post-process_searches_2.

<search id="myBaseSearch">
  <query>index= source= | regex field1 | regex field2</query>
</search>
<row>...
---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...