Splunk Search

server status on dashboard

sphiwee
Contributor

Good day everyone

 

How can I visualize and edit this query to show the status of our servers, ONLINE/OFFLINE ?

 

sphiwee_0-1599039265647.pngsphiwee_0-1599039265647.png

 

Labels (7)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sphiwee,

you can see in Dashboard Examples (https://splunkbase.splunk.com/app/1603/) in the "Table Icon Set (Rangemap)" dashboard how to display status using an icon instead a value.

In few words, you have to add to your app a css and a js (that you can find in Dashboard Examples) called by the dashboard

 

<form script="table_icons_rangemap.js" stylesheet="table_decorations.css">

 

then you have to assign an id at your table:

 

 <table id="table1">

 

At the end, you have to add to your search the rangemap command, something like this:

 

index=intau_workfusion host=*
| stats dc(ClusStatus) AS statuses BY host
| rangemap field=statuses severe=0-1 low=2-1000000000 default=severe
| table host range

 

In this way if statuses=0 or 1 you have a red icon and statuses>1 you have a green icon.

if you want to change the name of the range column, you have to modify also the table_icons_rangemap.js file.

Remember to restart Splunk after you added css and js to the app and reload the page at every change in the dashboard otherwise you don't see the icons.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...