官术网_书友最值得收藏!

Creating your first dashboard

Now that we have data ingested, it is time to use it in order to derive something meaningful out of it. You are still in the Destinations app, correct? We will show you the basic routine when creating new dashboards and dashboard panels.

Copy and paste the following search query in the Search Field, then hit Enter:

SPL> index=main /booking/confirmation earliest=-24h@h | timechart count span=15m

After the search results render, click on the Visualization tab. This will switch your view into visualization so you can readily see how your data will look. By default, it should already be using the Column Chart as shown in the following screenshot. If it does not, then use the screenshot as a guide on how to set it:

Now that you can see your Column Chart, it is time to save it as a dashboard. Click on Save As in the upper-right corner of the page, then select Dashboard Panel as shown in the following screenshot:

Now let's fill up that dashboard panel information, as seen in the following screenshot. Make sure to select the Shared in App in the Dashboard Permissions section:

Finish up by clicking View Dashboard in the next prompt:

You have created your very first Splunk dashboard with a panel that tells you the number of confirmed bookings in the last 24 hours at 15-minute intervals. Time to show it to your boss!

Take that well-deserved coffee break. You now have a fully-functional Splunk installation with live data. Leave Splunk running for 2 hours or so. After a few hours, you can stop Splunk if you need to rest for a bit to suppress indexing and restart it when you're ready to proceed into the next chapters. Do you recall how to control Splunk from the command line?

C:\> C:\Splunk\bin> splunk stop
C:\Splunk\bin> splunk start
主站蜘蛛池模板: 静乐县| 洛浦县| 九寨沟县| 习水县| 连山| 莱芜市| 和顺县| 垫江县| 资溪县| 平山县| 无棣县| 八宿县| 昔阳县| 张北县| 梓潼县| 特克斯县| 修水县| 阿勒泰市| 五峰| 太谷县| 丹阳市| 工布江达县| 宣化县| 萨迦县| 清远市| 利津县| 南陵县| 郧西县| 黄山市| 泾源县| 聂荣县| 汉中市| 宣恩县| 伊春市| 酉阳| 渭南市| 孟津县| 通化市| 牙克石市| 荆门市| 汤阴县|