We import vulnerability scan data into splunk on a weekly basis and report back in a trellis'd timechart dashboard. We use tokens to set criteria like segment, risk, and vulnerability type to produce timecharts of each of the count of named vulnerabilities over the last 30 days. Execs want (of course) red, yellow and green single value of current count and movement from the max count day of the last 30 by Name of Vulnerability. Experimented with stats using max(count) unsuccessfully. Here is the functional bits of my search that don't involve all of the qualification I do against known risk accepted or the criteria. What do I need to turn this into single value chart(s) with the latest count and the delta from the max daily entry in the last 30 days?
index=nessus | dedup _time,extracted_Host,Name | table _time,Name| timechart cont=FALSE count(extracted_Host) by Name
... View more