Knowledge Management

User Navigation flow

reverse
Contributor

In my logs - I have session id and page id ..

I want to see users' Navigation chart..
Please guide.

Tags (2)
0 Karma
1 Solution

DavidHourani
Super Champion

Hi @reverse,

Sankey can be found here :
https://splunkbase.splunk.com/app/3112/

And resources on how to use it is here :
https://docs.splunk.com/Documentation/SankeyDiagram/1.3.0/SankeyDiagramViz/SankeyIntro

Do you need help writing your SPL ?

Cheers,
David

View solution in original post

DavidHourani
Super Champion

Hi @reverse,

Sankey can be found here :
https://splunkbase.splunk.com/app/3112/

And resources on how to use it is here :
https://docs.splunk.com/Documentation/SankeyDiagram/1.3.0/SankeyDiagramViz/SankeyIntro

Do you need help writing your SPL ?

Cheers,
David

reverse
Contributor

Yes please

0 Karma

DavidHourani
Super Champion

Hi @reverse, sure thing, please share one line of logs as an example so we can build your search for Sankey. As shown here :
https://docs.splunk.com/Documentation/SankeyDiagram/1.3.0/SankeyDiagramViz/SankeySearchDataFormat
your search should look like this :

... | stats <stats_function>(<size_field>) [<stats_function>(<color_field>)] by <source_category_field> <target_category_field>

DavidHourani
Super Champion

Hi @reverse, what do you need the chart to look like ?

0 Karma

reverse
Contributor

Like sankey

0 Karma

niketn
Legend

@reverse you will have to provide more details like your data sample and existing query for us to assist you better. Please mock/anonymize any sensitive information.

The Sankey Custom Visualization also comes with sample query which you can refer to, in order to come up with your own query.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...