Hi All, Can I change cluster colours based on such code? | eval clusterGroup=case(bgp_state="Down","red",bgp_state="down","red",bgp_state="Up","green",bgp_state="up","green",bgp_state="null",...
Hi, I have created a Cluster Map that show number of counts based on number of ASA blocked actions. The circle size is based on number of hits. A bigger circle represent more c...
I need to make the heat map viz larger then 1000px, something close to 1500 or maybe even as much as 2000px. It looks like there may be a cap set at 1000px? I was using the "height" o...
I am using Heat Map Viz v1.5.0 with Splunk Ent. v9.4.4. When a user hovers over the heat map you cannot scroll up or down in the dashboard to panels that might be above or below a heat map...
Any reason why this can't be visualized in a geo cluster map? source="udp:514" index="syslog" NOT src_ip IN (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 17.0.0.0/8) action=DROP src_ip!="162.159.192.9...
Hi All,
I need help building a SPL that would return all available fields mapped to their sourcetypes/source
Looking across all Indexers crawling through all indexes index=*
I currently u...
...estlookup. While it works the index and sourcetype does not line up with the results. Mapping I found handles this SPL a little different than a normal search, location of the stats c...
Hello, I am looking at the attached node flow map. I am not sure why the node is grey. I am assuming no data? but both the node and the line to it show metrics. So how come the node is grey and c...
Hi All, Has anyone managed to map CrowdStrike Falcon FileVantage (FIM) logs to a Datamodel; if so could you share your field mappings? We were looking at he Change DM, would this be the best o...