Dashboards & Visualizations

Create dashboard and relatorio

fiveitsplunk
Explorer

Hello,

I would like to create 03 reports, but I have difficulties.
What happens, I need to create:
- Calls that are not answered by extension;
- Calls that are answered by extension successfully;

  • Calls made by extension successfully;
  • Unsuccessful extension calls;

But I notice that I can't filter by time, because there are links
  00:00:00, so I can't create a report using just the "status" of the call because it usually has "normal clean call".

It is possible to make a query in the way that, define that the calls "received" by time, and consider that with the value 00:00:00 s;

Att,
Richard

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps this will get you started.

index=foo duration="00:00:00" cause_description=* | table _time cause_description
---
If this reply helps you, Karma would be appreciated.
0 Karma

fiveitsplunk
Explorer

I could not resolve with this condition

richgalloway
SplunkTrust
SplunkTrust

What do you get? Did you make any necessary changes for your environment (correct index and field names) ?

---
If this reply helps you, Karma would be appreciated.
0 Karma

fiveitsplunk
Explorer

What I'd like to create is a report where you filter:
Call that came in and was not answered by anyone, in this case those that have the time value 00:00:00;alt text

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It would help if you shared some sample events, sanitized as necessary.

---
If this reply helps you, Karma would be appreciated.
0 Karma

fiveitsplunk
Explorer

It is possible to create a query, containing only calls with "zero duration" and the cause of the call.
"cause_description"?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...