Reporting

Feeding Sparkline with Data Model

splunkbeginner2
Path Finder

Hello,

for a dashboard I will need to display a sparkline with entries blocked / Accessed by an ACL from the Cisco IOS app. Because of the availability of data models I would like to use them to access the data. Unfortunately I am currently not able to create a sparkline that displays what i wanted.

I am able to get 9 charts that can display when each of the values was reached
(e.g.
2 hits at: 10:10, 10:30,10:40
3 hits at 10:20,
4 hits at: 10:50, 11:00
)

[All numbers displayed in a graph]

How could I get this data into a single graph?

| pivot Cisco_IOS_Event Blocked_Access_List_Event Blocked_Access_List_Event AS "val" SPLITROW _time AS _time PERIOD auto SORT 0 _time ROWSUMMARY 0 COLSUMMARY 0 NUMCOLS 0 SHOWOTHER 1  |                        eval count=val | eval name="name" | eval Time=_time|chart sparkline by val

Thanks for your help!

Regards!

0 Karma
1 Solution

splunkbeginner2
Path Finder

I fixed it. The solution was the following:

  1. I debugged the source of the Cisco IOS App. They use saved searches.
  2. Open Search in Splunk -> Settings->Searches --> Cisco uses the old notation.
  3. Using the old scheme of notation:

search index="cisco-firewall" action="blocked" | chart sparklines

Simple, but works. However I have to admit that I would have preferred a solution with the data model.

Best Regards!

View solution in original post

0 Karma

splunkbeginner2
Path Finder

I fixed it. The solution was the following:

  1. I debugged the source of the Cisco IOS App. They use saved searches.
  2. Open Search in Splunk -> Settings->Searches --> Cisco uses the old notation.
  3. Using the old scheme of notation:

search index="cisco-firewall" action="blocked" | chart sparklines

Simple, but works. However I have to admit that I would have preferred a solution with the data model.

Best Regards!

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...