I am looking for the hour in which the maximum number of events take place. My search looks like
... | timechart span=1h sum(count) as Max | sort -Max
From this, I know how to get both the amount of events in that hour and the hour itself, but I would like to show these fields in the same singlevalue panel.
I think there is a way to do this. I tried modifying the .js in "Single Value Trend" from "Splunk 6.x Dashboard Examples", but had no success, so I wonder if somebody could help me.
Any tip will be appreciated, thanks!
... View more