Skip to content

Commit

Permalink
feat: change avg() to sum() in PANEL_EVENTS_INGESTED_BY_SOURCETYPE_TE…
Browse files Browse the repository at this point in the history
…MPLATE panel (#1028)

Changes for "Events ingested by sourcetype" panel:
* Change SPL function from avg() to sum()
* Change chart type from line to column
  • Loading branch information
sgoral-splunk authored Jan 25, 2024
1 parent bc5ee28 commit c738634
Show file tree
Hide file tree
Showing 4 changed files with 7 additions and 7 deletions.
2 changes: 1 addition & 1 deletion docs/dashboard.md
Original file line number Diff line number Diff line change
Expand Up @@ -78,7 +78,7 @@ Executes the following search:

```
index=_internal source=*<addon_name>* action=events_ingested
| timechart avg(n_events) by sourcetype_ingested
| timechart sum(n_events) by sourcetype_ingested
```

> Note: <addon_name> is being replaced by the actual value during the build time.
Expand Down
4 changes: 2 additions & 2 deletions splunk_add_on_ucc_framework/dashboard.py
Original file line number Diff line number Diff line change
Expand Up @@ -75,11 +75,11 @@
<chart>
<search>
<query>index=_internal source=*{addon_name}* action=events_ingested
| timechart avg(n_events) by sourcetype_ingested</query>
| timechart sum(n_events) by sourcetype_ingested</query>
<earliest>$log_time.earliest$</earliest>
<latest>$log_time.latest$</latest>
</search>
<option name="charting.chart">line</option>
<option name="charting.chart">column</option>
<option name="charting.drilldown">none</option>
</chart>
</panel>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -31,11 +31,11 @@
<chart>
<search>
<query>index=_internal source=*splunk_ta_uccexample* action=events_ingested
| timechart avg(n_events) by sourcetype_ingested</query>
| timechart sum(n_events) by sourcetype_ingested</query>
<earliest>$log_time.earliest$</earliest>
<latest>$log_time.latest$</latest>
</search>
<option name="charting.chart">line</option>
<option name="charting.chart">column</option>
<option name="charting.drilldown">none</option>
</chart>
</panel>
Expand Down
4 changes: 2 additions & 2 deletions tests/unit/test_dashboard.py
Original file line number Diff line number Diff line change
Expand Up @@ -40,11 +40,11 @@
<chart>
<search>
<query>index=_internal source=*splunk_ta_uccexample* action=events_ingested
| timechart avg(n_events) by sourcetype_ingested</query>
| timechart sum(n_events) by sourcetype_ingested</query>
<earliest>$log_time.earliest$</earliest>
<latest>$log_time.latest$</latest>
</search>
<option name="charting.chart">line</option>
<option name="charting.chart">column</option>
<option name="charting.drilldown">none</option>
</chart>
</panel>
Expand Down

0 comments on commit c738634

Please sign in to comment.