Splunk® Enterprise

Analytics Workspace

Splunk Enterprise version 8.1 will no longer be supported as of April 19, 2023. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Types of data in the Analytics Workspace

The Analytics Workspace Data panel contains the data sources that you have available for visualization and analysis. These data sources are organized by data type. Supported data types are metrics, datasets, and alerts.

About metrics data

Click the Metrics tab in the Data panel to view a list of metrics. Metrics data sources are listed in a tree structure according to their metric_name prefixes.

For example, the following image shows Metrics data sources that contain the aws prefix in their metric_name values.

This screen image shows the Metrics data sources in the Data panel that contain the aws prefix.

If two metrics with the same name are ingested into different indexes, they appear aggregated in the Data panel. To distinguish these metrics in the workspace, see Distinguish metrics with the same metric name.

The Analytics Workspace does not currently support metric roll-ups.

To learn more about metrics data, including metrics ingest, see Overview of Metrics in the Metrics Manual.

For information about converting log data into metrics data, see Convert event logs to metric data points in the Metrics Manual.

About datasets

Click the Datasets tab in the Data panel to view a list of datasets. Datasets are listed in a tree structure according to the dataset name. Click a dataset name to see a list of fields for the dataset. Numeric fields are indicated by the hash (This screen image shows the hash icon.) icon, whereas string fields are indicated by the alpha (This screen image shows the alpha icon.) icon.

For example, the following image shows a list of fields for the Audit dataset.

This screen image shows the Audit dataset fields in the Data panel.

Only accelerated datasets are supported in the Analytics Workspace. See Accelerate data models in the Knowledge Manager Manual for more information.

For more information about datasets, see Dataset types and usage in the Knowledge Manager Manual.

About alerts

Click the Alerts tab in the Data panel to view a list of alerts that were created in the Analytics Workspace. The Alerts tab includes alerts that you created and alerts that have been shared with you. Alerts are listed in a tree structure according to the data source they use. Click a data source name to see a list of alerts that are based on it.

For example, the following image shows a list of Analytics Workspace alerts for the aws.ec2.CPUUtilization metric.

This screen image shows the Analytics Workspace alerts for the aws.ec2.CPUUtilization metric listed in the Data panel.

For more information about Analytics Workspace alerts, see Alerts in the Analytics Workspace.

Last modified on 08 January, 2021
 

This documentation applies to the following versions of Splunk® Enterprise: 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.10, 8.1.11, 8.1.12, 8.1.13, 8.1.14


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters