Splunk Search

server status on dashboard

sphiwee
Contributor

Good day everyone

 

How can I visualize and edit this query to show the status of our servers, ONLINE/OFFLINE ?

 

sphiwee_0-1599039265647.png

 

Labels (7)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sphiwee,

you can see in Dashboard Examples (https://splunkbase.splunk.com/app/1603/) in the "Table Icon Set (Rangemap)" dashboard how to display status using an icon instead a value.

In few words, you have to add to your app a css and a js (that you can find in Dashboard Examples) called by the dashboard

 

<form script="table_icons_rangemap.js" stylesheet="table_decorations.css">

 

then you have to assign an id at your table:

 

 <table id="table1">

 

At the end, you have to add to your search the rangemap command, something like this:

 

index=intau_workfusion host=*
| stats dc(ClusStatus) AS statuses BY host
| rangemap field=statuses severe=0-1 low=2-1000000000 default=severe
| table host range

 

In this way if statuses=0 or 1 you have a red icon and statuses>1 you have a green icon.

if you want to change the name of the range column, you have to modify also the table_icons_rangemap.js file.

Remember to restart Splunk after you added css and js to the app and reload the page at every change in the dashboard otherwise you don't see the icons.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...