Hello,
I want to create a dashboard that has
What I am using for the dashboard is a file that has..
2015-05-22 00:5:02,318 INFO Begin Payment
2015-05-22 00:10:17,090 INFO Finished Payment
It will be in that format... <Date> <time> <info or error> <name>
Right now I have a table that shows all the errors or failures so I used...
source="LOCATION" ERROR OR FAIL*
The visulization (chart and boxes[I'm hoping this is the single value panels you want]) can be created per your requirement. More details on the same here .http://docs.splunk.com/Documentation/Splunk/6.1.6/Viz/PanelreferenceforSimplifiedXML
For preparing the required data to be shown in these visualizations, you would have to write a search to generate the data. From the sample data, you would need to generate some sort of transaction (see transaction command here http://docs.splunk.com/Documentation/Splunk/6.1.6/SearchReference/Transaction).
The visulization (chart and boxes[I'm hoping this is the single value panels you want]) can be created per your requirement. More details on the same here .http://docs.splunk.com/Documentation/Splunk/6.1.6/Viz/PanelreferenceforSimplifiedXML
For preparing the required data to be shown in these visualizations, you would have to write a search to generate the data. From the sample data, you would need to generate some sort of transaction (see transaction command here http://docs.splunk.com/Documentation/Splunk/6.1.6/SearchReference/Transaction).
Thank you somesoni2! Exactly what I needed
@somesoni2 is there any way to do these graphs and tables without XML?
What version of Splunk you're using?
6.1.6.2 is the version