Getting Data In

Base Searches for Dashboards using Splunk Metrics

splunkninga2
New Member

Hi all,

My team recently got metric data into Splunk and I created several dashboards with various drop down tokens for metric names as well as host. My next step was to try and create a logical base search with post processing searches to reduce the amount of concurrent searches running within the panels. I've been having a heck of a time getting a proper base search to work when it struck me:

These metric searches on the panels almost always complete in 1 second and there aren't too many metric points being generated per day. Are base searches even worth it for this type of data? I know that base searches is a best practice for dashboards, but these panels still load almost instantly even when concurrent dashboards are being run. Trying to get some potential insight before I go down rabbit holes again to get a base search and post processing searches to work.

Appreciate any feedback 😄

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...