The Splunk single value visualization is used to represent information or the result of the Splunk command, which is basically a single value that can be a number/statistics/single information on which an inference can be made. Like a single value, visualization can be used to represent a number of errors, number of visitors, number of fraud detected, number of failures, last error occurred, top users, number of invalid accounts, time of last failure, and so on.
Splunk 6.3 has enhanced single value visualization with various functional customizations such as adding trend indicators, Sparkline, labels, and other aesthetic customizations by adding custom CSS. You will now learn how to create single value visualization on the Splunk Web console.
The following is the list of customizations and formatting that can be done on a single value:
search
command has a timechart
command, then Sparkline and Trend can be enabled from the Format option. Sparkline and Trend can be formatted using the Color option and conditional coloring can also be done on the basis of the value using the Format option. The below image shows the single value with Sparkline and Trend indication:For example, the visitor information data from a test web server is used to showcase how a single value can be used. The following search query on Splunk will return the average number of visitors visiting the web server, and since the timechart
command is used, trend and Sparkline can also be enabled. Now, this information can be displayed using a single value; you just need to choose it from the list of visualizations, as shown at the start of the chapter.
Our search query is as follows:
||inputcsv webserver.csv | eval _time=strptime (date, "%e-%b-%y") |timechart avg(Visitors) span=7d
This query will produce the following output:
So, single value visualization can be used to depict required information along with trend and Sparkline. Splunk 6.3 gives all the formatting and customization right from the Splunk web console Format option itself. Conditional coloring, that is, the color of the value will change depending on the range in which the value lies or on the basis of the trend. The precision and thousand separators can be enabled and configured from the Format option.
52.15.59.163