Splunk Search

How do I display text in a dashboard panel based on the event coverage percentage in its corresponding pivot?

splunkwiz
New Member

I want to display text in the middle of the panel that is based on the value of a status code or its percentage.

I've seen

https://answers.splunk.com/answers/522255/how-to-display-text-message-in-the-center-of-a-das.html?ut...

but I'm not sure what token I would use in my case.

I currently use eval and fields commands in my search, similar to

https://answers.splunk.com/answers/525122/how-to-display-data-value-in-percentage.html?utm_source=ty....

When I do it this way my new dashboard panel is based off a direct search. I also need the % after the number, so currently I've stuck the % as a unit to display.

However, I'd like to use the event coverage percentage. My current dashboard panel is based off a pivot. When I open this in a search, under events, I can click the status code field on the left and it displays the value, count, and %. How do I display this percentage in my panel per each value? How do I display the percentage based on 100% or the value (200 status code)?

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...