Splunk® Enterprise

Dashboards and Visualizations

Data structure requirements for visualizations

Visualizations require search results in specific formats or data structures. Write queries to generate results in the correct format for the visualization that you are building.

This topic provides an overview of data structures for visualizations. To learn about requirements for a specific visualization and how to generate results in the correct format, see one of the following topics.

Events list
Using events lists
Table visualizations
Generate a table
Charts
Pie chart
Column and bar charts
Line and area charts
Scatter chart
Bubble chart
Single value
Generate a single value
Gauges
Using gauges
Maps
Mapping Data

For an overview of visualization options, see the Visualization Reference in this manual.

Data and formatting requirements

Depending on the visualization that you are creating, you can use specific search commands to generate results in the correct format. For example, many visualizations require a search using transforming commands, such as stats, chart, timechart, or geostats to render.

Charts visualize one or more data series, or related data points. Depending on the chart type or complexity, the number and ordering of data series can vary.

Single value and gauge visualizations represent a single numerical value.

Maps combine a query and other data components, including data with coordinates or place information, lookup definitions, and geographical markup files.

Using the statistics table

When creating a visualization, you can check the Statistics table after running a search to make sure that result fields are generated correctly. The number and order of Statistics table columns show you the data structure that a search generated.

Additional information

Review specific visualization topics to check data format requirements and query recommendations.

To learn more about search commands that can generate visualizations, see the following topics.

Last modified on 10 June, 2019
Visualization reference   Using events lists

This documentation applies to the following versions of Splunk® Enterprise: 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.13, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10, 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.11, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.1.5, 9.1.6, 9.1.7, 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 9.3.0, 9.3.1, 9.3.2, 8.1.10, 8.1.12, 8.1.13, 8.1.14


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters