Splunk Search

Adding multiple sparklines in a search

theouhuios
Motivator

I am trying to add multiple sparklines to a search. When I use this

stats sparkline avg(ProcV) as ProcV  sparkline avg(DiskV) as DiskV  sparkline avg(ProcQueue) as ProcQueue avg(DiskQueue) as DiskQueue avg(ByteT) as ByteT avg(Curcon) as Curcon avg(RWT) as RWT

it only shows sparkline for avg(ProcV) but ignoring others. Thats the same when I use chart.

So I am trying to append the data to the present search results, instead of placing the sparklines for those 3 counters beside the hosts, it creates another set of host fields and then places the saprklines.

| stats avg(ProcV) as ProcV  avg(DiskV) as DiskV   avg(ProcQueue) as ProcQueue avg(DiskQueue) as DiskQueue avg(ByteT) as ByteT avg(Curcon) as Curcon avg(RWT) as RWT
avg(ASP) as ASP avg(ASPv2) as ASPv2 avg(ASPv4) as ASPv4 by host|append [search earliest=-30m@m latest=@m  sourcetype="Perfmon:*" serverType= "B2C WEB APP" counter="% Processor Time" OR counter="Available Kbytes" OR counter="Current Connections"|eventstats avg(Value) as AvgValue by host counter |chart sparkline avg(AvgValue) over host by counter | fields - avg(AvgValue)*|sort - host]

Here is the image on what it does

alt text

Tags (1)
0 Karma

jonuwz
Influencer

Try :

stats sparkline(avg(ProcV)) as ProcV  sparkline(avg(DiskV)) as DiskV  sparkline)avg(ProcQueue)) as ProcQueue avg(DiskQueue) as DiskQueue avg(ByteT) as ByteT avg(Curcon) as Curcon avg(RWT) as RWT by host
0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>