Splunk® Light

Search and Reporting Examples

Download manual as PDF

Download topic as PDF

Add a single value panel to a dashboard

Some searches return a single value output. You can visualize this data with Splunk Light's single value display options. In this scenario, use your data to determine the number of root users.

  1. Click Search in the Splunk Light bar.
  2. Type the following into the search bar.

    sourcetype=ps root | stats count

  3. Click the Visualization tab.
  4. In the chart type menu, select Single Value (appears as a 42). You can format the color of the display for specific number ranges, indicating when a value gets too high or too low.
  5. (Optional) To see your data as a radial gauge, select Radial Gauge from the chart type menu. Format it for the correct number ranges.
  6. Click Save As, and click Dashboard Panel.
  7. Add your visualization to your existing dashboard.
  8. Name your panel Number of root users.
  9. Click Save.
  10. To view your changes, click View Dashboard.

Your dashboard now contains six panels: two prebuilt panels, an in-line search panel, two table panels, and a single value data panel.

Last modified on 31 July, 2018
Add tables to a dashboard
Edit dashboard panels

This documentation applies to the following versions of Splunk® Light: 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.5.0, 6.5.1, 6.5.2, 6.5.3, 6.5.1612 (cloud service only), 6.6.0, 6.6.1, 6.6.2, 6.6.3, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters