try something like this for the pie chart:
index=linux* | rex field=source ".*\/(?<device_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\/.*" | stats latest(_time) as Last_Time by device_ip
|join device_ip type=left
[| inputlookup SwiftDeviceIPHostname |lookup SwiftCompliance hostname AS NewServerName OUTPUT service
| table NewServerName,InsideIP,MgmtIP,service | eval Host=lower(NewServerName) | eval device_ip=coalesce(MgmtIP,InsideIP)|lookup SwiftCompliancePolicy Host OUTPUT Policy| search Policy=linux* service !=Remove* service != "*A1c" service !=*2HOP Host!= ace* ]
| eval DateDiff=(now()-Last_Time)/(24*3600)
| eval Compliant = if(DateDiff <=1,"Compliant","Non Compliant")
| chart count by Compliant
| eval Compliant=Compliant." : ".count
and see what you get. I think one issue you might be facing is the search time. I know I used to have issues with searches that used too much memory or too much time that the PDFs wouldn't render properly. If this works, use similar logic to re-write the table SPL. Use the job inspector to check the search optimization. Let me know if there are any questions or if it isn't working, it'll be helpful to have some sample data to work with.
... View more