Splunk Search

How do I get the dashboard to show  ONLY the highest count for the day?

woodlandrelic
Path Finder

HI 

So I have this dashboard showing the below. 

HBSS      ACAS        CMRSACAS    CMRSHBSS
89              92               84                          77

MY question is how do I get the dashboard to show  ONLY the highest count for the day. Since the dashboard are updated daily? Any help will be fantastic.

Thanks

Labels (1)
0 Karma
1 Solution

Tom_Lundie
Contributor

It would be helpful if you could share some of your upstream SPL (and maybe even some sample data). This might help us to generate efficient SPL for your use-case.

That being said, here is a way to convert the table you provided into the largest device count.

 

| transpose column_name=devices
| rename "row 1" as count
| eventstats max(count) as max_count
| where count=max_count

 

This has the ability to return multiple rows if they have the largest count in common. You could use | head 1 after to limit it to one result.

View solution in original post

Tom_Lundie
Contributor

It would be helpful if you could share some of your upstream SPL (and maybe even some sample data). This might help us to generate efficient SPL for your use-case.

That being said, here is a way to convert the table you provided into the largest device count.

 

| transpose column_name=devices
| rename "row 1" as count
| eventstats max(count) as max_count
| where count=max_count

 

This has the ability to return multiple rows if they have the largest count in common. You could use | head 1 after to limit it to one result.

woodlandrelic
Path Finder

Hi @Tom_Lundie 

So I figure it out and replace the individual search with
 |search system_id=$system_id$

| transpose column_name=devices
| rename "row 2" as count
| eventstats max(count) as max_count
| where count=max_count
| table max_count
| head 1

 

 

Thank you very much

Tags (1)
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...