gauge command to transform your search results into a format that can be used with the gauge charts. All gauge charts visualize a single aggregated metric, such as a count or a sum.
The output of the
gauge command is a single numerical value stored in a field called
x. You can specify a range to display in the gauge, or use the default range 0 - 100.
For more information about using the
gauge command with the gauge chart types, see the Chart section in the Using gauges in the Data Visualization Manual.
- gauge <value> [<range_val1> <range_val2> ...]
- Syntax: field_name | <num>
- Description: A numeric field or literal number to use as the current value of the gauge. If you specify a numeric field, the
gaugecommand uses the first value in that field as the value for the gauge.
- range values
- Syntax: <range_val1> <range_val2> ...
- Description: A space-separated list of two or more numeric fields or numbers to use as the overall numeric range displayed in the gauge. Each range value can be a numeric field name or a literal number. If you specify a field name, the first value in that field is used as the range value. The total range of the gauge is from the first
range_valto the last
range_val. See Usage.
- Default range: 0 to 100.
You can create gauge charts without using the
gauge command, as long as your search results in a single value. The advantage of using the
gauge command is that you can specify a set of range values instead of using the default range values 0 - 100.
If you specify range values, you must specify at least two values. The gauge begins at the first value and ends at the last value that you specify.
If you specify more than two
range_val arguments, the intermediate range values are used to split the total range into sub-ranges. These sub-ranges are visually distinct using by using different colors for each subrange.
Ranges are output into a series of fields called
y2, and so on.
If you do not specify range values, the range defaults to a low value of 0 and a high value of 100.
If a single range value is specified, it is ignored.
With a gauge chart, a single numerical value is mapped against a set of colors. These colors can have particular business meaning or business logic. As the
value changes over time, the gauge marker changes position within this range.
The color ranges in the gauge chart are based on the range values that you specify with the
gauge command. When you specify range values, you define the overall numerical range represented by the gauge and you can define the size of the colored bands within that range. If you want to use the color bands, add four range values to the search string. These range values indicate the beginning and end of the range. These range values also indicate the relative sizes of the color bands within this range.
1. Create a gauge with multiple ranges
Count the number of events and display the count on a gauge with 4 ranges, where the ranges are 0-750, 750-1000, 1000-1250, and 1250-1500.
Start by generating the results table using this search. Run the search using the Last 15 minutes time range.
index=_internal | stats count as myCount | gauge myCount 750 1000 1250 1500
The results appear on the Statistics tab and look something like this:
Click on the Visualizations tab. There are three types of gauges that you can choose from: radial, filler, and marker. The following image shows a radial gauge.
For more information about using the
gauge command with the gauge chart type, see the Gauges section in Dashboard and Visualizations.
Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has using the gauge command.
This documentation applies to the following versions of Splunk® Enterprise: 5.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0.15, 5.0.16, 5.0.17, 5.0.18, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.1.0, 7.1.1, 7.1.2