Splunk® Enterprise

Dashboards and Visualizations

Download manual as PDF

Download topic as PDF

Visualization reference

Compare options and select a visualization to show the data insights that you need.

To quickly view the most fundamental overview of common visualizations and their use cases, note that you can access the Splunk Dashboards Quick Reference guide by clicking the link in Getting started.

Visualization Usage To learn more see
Events list

Event list viz example.png

Show the events that a search generates.
  • Show events without additional processing.
  • Show extracted fields and values directly in a dashboard.
  • Users can click on event fields or timestamps to open a more specific search.
Using events lists
Table

Table general example.png

Compare and aggregate field values.
  • Isolate one or more specific fields from search results.
  • Add formatting to highlight trends or patterns in specific fields.
Table visualization overview
Charts

6.4 Stacked area chart example.png

Visualize one or more dimensions in a data set.
Use one of the following chart types depending on how many dimensions, or fields, you are visualizing.
  • Pie
  • Area, line, column, bar
  • Bubble and scatter
Chart overview
Single value

Fluttershy single value background color mode.png

Show an aggregated metric in context.
  • Track recent changes or trends in real time.
  • Use colors to add context dynamically.
Single value overview
Gauges

6.4 marker gauge example.png

  • Show an aggregated metric against a range.
  • Track a metric as it approaches a specific target.
Using gauges
Maps

6.3.0 choropleth screenshot divergent us states.png

Visualize data with geographic coordinates.
  • Use a Choropleth map to show and compare regional trends or concentrations.
  • Use a marker map to plot geographic data.
Mapping data
Custom visualizations Analyze and represent unique data sets.

An admin must install custom visualization apps to make them available for Splunk users.
See Custom visualizations for more details.
PREVIOUS
Getting started
  NEXT
Data structure requirements for visualizations

This documentation applies to the following versions of Splunk® Enterprise: 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 7.0.0


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters