Splunk Search

Using Sparklines with mstats

eddieddieddie
Path Finder

How do I draw a Sparkline from data that comes from a metrics index (ie accessed via the mstats command)?

I've tried various combinations of:

| mstats span=5m latest(LogicalDisk.%_Free_Space) as FreePercentSpace WHERE index=metrics_index host=HOSTYMCHOSTFACE instance="*:"
| stats sparkline count by instance

And tried adding "prestats=true" to the end of the mstats command but still nothing happens. I assume there is some sort of intermediate command I need to put between the two lines to make the data palatable for stats (or chart) to process?

Thanks
Eddie

Labels (1)
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...