Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Displaying stats count as single value but with sparkline & trend indicator

$
0
0
Hi fellow Splunkers, I've read Single Value support docs and it seems to have distinct application for Stats or Timechart. When I use timechart: sourcetype="error log" severity=ERROR someErrorcode | timechart count it displays sparkline and trend correctly, however for the single value, it's using the Count of that error at the specific instance of time as opposed to the indicated desired span of time I want to try to combine the two or have an end result that leverages both stats and timechart. I want to use the total count of events found in my span of time as my single value display but I also want a sparkline/heartbeat below showing the timeline of the event occurrences during my span and an up/down trend indicator examples available in the Docs are too simplistic and seems to only use values that are already single values - ie. close stock price, temperature... Thanking you for your help in advance!!!

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>