Splunk Search

Sankey diagram for order paths based on message field per orderId?

smahoney
Path Finder

This seems like it should be simple, but all I ever get is a 2 column sankey visualization with the starting event then the end event ribbons where the ribbons represent the count of events.

Is there any way to create a visualization where each orderId starts with a message like "order received", then that order can process through 5-10 other messages, but not all orders will do this.

I want to visualize how many say stop at message 3, while also seeing the paths from message three through the process for those that don't end there.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...