Hi,
I have a chart that works, but mgmt wants the host values to map to something more meaningful. Is there a way to do this?
My search is this:
index=coreops sourcetype=snmpinfo source="/usr/local/nsmutils/varlog/splunk_cgk_sessions.log" | head 9 | chart sum(CONNECTIONS) as CONNECTIONS by HOST | eval H=HOST | eval HOST="" | xyseries HOST H CONNECTIONS
You might consider doing a lookup on HOST?
lookup worked. The customer didn't like the name of the hosts, so we mapped it via a lookup.
Well how would you define "useful" in your scenario?