how do i specify a particular value to be displayed in single value visualization chart? i only want the totalCount (success+errors) to display as the single value in the chart:
index=nonprod_applogs source="*test.log*" ("purchase success") OR ("purchase failed") |
dedup requestMarker |
stats count(eval(searchmatch("purchase success"))) as successCount
count(eval(searchmatch("purchase failed"))) as errorCount |
eval totalCount = successCount + errorCount
@jaj why not try just | stats count as totalCount
? You have already filtered the required events:
index=nonprod_applogs source="*test.log*" ("purchase success") OR ("purchase failed")
| dedup requestMarker
| stats count as totalCount
@jaj why not try just | stats count as totalCount
? You have already filtered the required events:
index=nonprod_applogs source="*test.log*" ("purchase success") OR ("purchase failed")
| dedup requestMarker
| stats count as totalCount
@niketnilay dang yes very true for totalCount thank you :bow:
HI,
I want to rewrite my previous answer:
try this. either add to your XML code on your dashboard the option field
have a look at the link under "single value"
https://docs.splunk.com/Documentation/Splunk/7.2.3/Viz/PanelreferenceforSimplifiedXML#single_value
or use the SPL command | fields totalCount
within your single value search on the dashboard
hi @dkeck! i appended that to the end of the query but it's only displaying "1"
updated my answer 🙂
@dkeck cool thanks for the amended response! :thumbsup: