Dashboards & Visualizations

replacing host values in a chart

a212830
Champion

Hi,

I have a chart that works, but mgmt wants the host values to map to something more meaningful. Is there a way to do this?

My search is this:

index=coreops sourcetype=snmpinfo source="/usr/local/nsmutils/varlog/splunk_cgk_sessions.log" | head 9 | chart sum(CONNECTIONS) as CONNECTIONS by HOST | eval H=HOST | eval HOST="" | xyseries HOST H CONNECTIONS

Tags (2)
0 Karma
1 Solution

bigtyma
Communicator

You might consider doing a lookup on HOST?

View solution in original post

bigtyma
Communicator

You might consider doing a lookup on HOST?

a212830
Champion

lookup worked. The customer didn't like the name of the hosts, so we mapped it via a lookup.

0 Karma

Ayn
Legend

Well how would you define "useful" in your scenario?

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...