Splunk Search

Adding multiple sparklines in a search

theouhuios
Motivator

I am trying to add multiple sparklines to a search. When I use this

stats sparkline avg(ProcV) as ProcV  sparkline avg(DiskV) as DiskV  sparkline avg(ProcQueue) as ProcQueue avg(DiskQueue) as DiskQueue avg(ByteT) as ByteT avg(Curcon) as Curcon avg(RWT) as RWT

it only shows sparkline for avg(ProcV) but ignoring others. Thats the same when I use chart.

So I am trying to append the data to the present search results, instead of placing the sparklines for those 3 counters beside the hosts, it creates another set of host fields and then places the saprklines.

| stats avg(ProcV) as ProcV  avg(DiskV) as DiskV   avg(ProcQueue) as ProcQueue avg(DiskQueue) as DiskQueue avg(ByteT) as ByteT avg(Curcon) as Curcon avg(RWT) as RWT
avg(ASP) as ASP avg(ASPv2) as ASPv2 avg(ASPv4) as ASPv4 by host|append [search earliest=-30m@m latest=@m  sourcetype="Perfmon:*" serverType= "B2C WEB APP" counter="% Processor Time" OR counter="Available Kbytes" OR counter="Current Connections"|eventstats avg(Value) as AvgValue by host counter |chart sparkline avg(AvgValue) over host by counter | fields - avg(AvgValue)*|sort - host]

Here is the image on what it does

alt text

Tags (1)
0 Karma

jonuwz
Influencer

Try :

stats sparkline(avg(ProcV)) as ProcV  sparkline(avg(DiskV)) as DiskV  sparkline)avg(ProcQueue)) as ProcQueue avg(DiskQueue) as DiskQueue avg(ByteT) as ByteT avg(Curcon) as Curcon avg(RWT) as RWT by host
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...