Splunk® Metrics Workspace (Legacy)

Using the Splunk Metrics Workspace

Types of data in the Splunk Metrics Workspace

The Metrics Workspace Data panel contains the data sources that you have available for visualization and analysis. These data sources are organized by data type. Supported data types are metrics, datasets, and alerts.

About metrics data

Click the Metrics tab in the Data panel to view a list of metrics. Metrics data sources are listed in a tree structure according to their metric_name prefixes.

For example, the following image shows Metrics data sources that contain the aws prefix in their metric_name values.

This screen image shows the Metrics data sources in the Data panel that contain the aws prefix.


If two metrics with the same name are ingested into different indexes, they appear aggregated in the Data panel. To distinguish these metrics in the workspace, see Distinguish metrics with the same metric name.

The Splunk Metrics Workspace does not currently support metric roll-ups.

To learn more about metrics data, including metrics ingest, see Overview of Metrics in the Metrics Manual.

For information about converting log data into metrics data, see Convert event logs to metric data points in the Metrics Manual.

About datasets

Click the Datasets tab in the Data panel to view a list of datasets. Datasets are listed in a tree structure according to the dataset name. Click a dataset name to see a list of fields for the dataset. Numeric fields are indicated by the This screen image shows the hash icon. icon, whereas string fields are indicated by the This screen image shows the alpa icon. icon.

For example, the following image shows a list of fields for the Audit dataset.

This screen image shows the Audit dataset fields in the Data panel.


Only accelerated datasets are supported in the Metrics Workspace. See Accelerate data models in the Knowledge Manager Manual for more information.

For more information about datasets, see Dataset types and usage in the Knowledge Manager Manual.

About alerts

Click the Alerts tab in the Data panel to view a list of alerts that were created in the Metrics Workspace. The Alerts tab includes alerts that you created and alerts that have been shared with you. Alerts are listed in a tree structure according to the data source they use. Click a data source name to see a list of alerts that are based on it.

For example, the following image shows a list of Metrics Workspace alerts for the aws.ec2.CPUUtilization metric.

This screen image shows the Metrics Workspace alerts for the aws.ec2.CPUUtilization metric listed in the Data panel.


For more information about Metrics Workspace alerts, see Alerts in the Splunk Metrics Workspace.

Last modified on 04 February, 2020
Navigating the Splunk Metrics Workspace   Charts in the Splunk Metrics Workspace

This documentation applies to the following versions of Splunk® Metrics Workspace (Legacy): 1.1.6, 1.1.7, 1.1.9


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters