Splunk Search

How to edit my visualization to display a chart overlay representing the percentage of failed logins for Windows?

jwalzerpitt
Influencer

Came across a Splunk blog post that talked about percentage of failed logins for Box (http://blogs.splunk.com/2015/08/25/splunking-box-data-user-authentications/) and I've been trying to adapt it to percentage of failed logins for Windows and I have the following search:

index=winevt (LogonType=2 OR LogonType=7 OR LogonType=10) (EventID=4624 OR EventID=4625) | stats count by _time EventType IpAddress | timechart count by EventType limit=10 usenull=f | eval pct_failed=AUDIT_FAILURE/(AUDIT_FAILURE+AUDIT_SUCCESS)*100 | eval pct_failed=round(pct_failed,1) | rename pct_failed AS "% Failed" 

For the visualization, I have a stacked column chart, but I'm not getting the line for the average like I see in the blog post. Any help would be appreciated.

Thx

0 Karma
1 Solution

cmerriman
Super Champion

here is how you get a chart overlay:
http://docs.splunk.com/Documentation/Splunk/6.5.0/Viz/Chartcontrols#Chart_overlay

In search, you click on 'Format > Chart Overlay' and under 'Overlay' in the fields you select 'pct_failed'
In a dashboard, if you're editing panels, you'd click on the little painbrush (Format) and Chart Overlay, just as in the step above.

View solution in original post

0 Karma

cmerriman
Super Champion

here is how you get a chart overlay:
http://docs.splunk.com/Documentation/Splunk/6.5.0/Viz/Chartcontrols#Chart_overlay

In search, you click on 'Format > Chart Overlay' and under 'Overlay' in the fields you select 'pct_failed'
In a dashboard, if you're editing panels, you'd click on the little painbrush (Format) and Chart Overlay, just as in the step above.

0 Karma

jwalzerpitt
Influencer

Awesome - thx for the reply and information!

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...