This app presents a form where a user can type a keyword such as error and find top/timecharts of the results by source, sourcetype, and host on a dashboard. The same search could be used for finding last week vs. this week comparisons, to see if there are any sources, sourcetypes, or hosts that go above standard deviation plus the average count of occurrences, and to see a donut chart dashboard distribution of different keywords by metadata. See the README for more details. Look under the Dashboard Menu for the Rare, Rare Punctuation, Cluster to find Anomalies, Outlier, Slope, Predict, Timewrap, Abstract of Events, Easy Button to find errors, and Baseline Forms.
(0)
Categories
Created By
Type
Downloads
Licensing
Splunk Answers
Resources