Splunk tile

About Splunk tiles

Splunk tiles offer you an easy way to display data from your Splunk instance in a SquaredUp DS dashboard.

SquaredUp DS Standalone Enterprise edition (or above) is required for access to the Splunk tile, ServiceNow tile, Azure App Insights tiles, High Availability, and Team Folders.
To upgrade please contact [email protected]
To check the license edition you are using see How to check which license key is being used.

How to configure a Splunk tile

If you don't already have a Splunk provider, you need to create one before you can configure a Splunk tile (How to add a Splunk provider).

  1. Add a new tile to a dashboard and click on Integrations > Splunk.
  2. Select the visualization for your Splunk tile and click next.

  3. Provider:
    Select your Splunk provider from the select provider drop-down and click next.

    You can only use providers of the same type as the tile. Providers of other types won't be shown in the select provider drop-down.

  4. Search:
    Enter your Splunk search query using the Search Processing Language (SPL).
     
    templates button:
    Allows you to import searches that are saved in your Splunk instance.

    Which templates are available in a Splunk tile depends on the permissions of the Splunk user account that is used in the configuration of the Splunk provider. Any search queries that this user can access in Splunk (for example, queries in saved searches, Splunk reports, dashboards, etc.) are visible as templates in Splunk tiles. For example, if you used Splunk User A for the configuration of Splunk provider A, a Splunk tile that uses Splunk provider A will show all templates that are visible to Splunk User A in Splunk.

    You can use the clock insert time value button

    to insert page timeframe and date variables in your query.

    The insert time value button inserts time values into the query. Any settings selected from the timeframe section are also applied to further filter down the results of the query. So time settings from both the query and the timeframe affect the results shown, and should be used with care or you may not see all the data you were expecting.

     

  5. Timeframe:

    The insert time value button inserts time values into the query. Any settings selected from the timeframe section are also applied to further filter down the results of the query. So time settings from both the query and the timeframe affect the results shown, and should be used with care or you may not see all the data you were expecting.


    Optionally, you can set the timeframe outside of the search:
    Specific timeframe:

    If you used a template, SquaredUp DS inherits the timeframe you set for the search in Splunk and puts it in the timeframe field as a specific timeframe.


    use page timeframe:
    A dynamic timeframe that depends on the current page timeframe.

     
  6. Configure the settings for the visualization you chose:
  7. Click done to save the tile.
    The tile now shows data according to your search.

Tips for using the page timeframe in Splunk tiles

Using page timeframe means your search query will adapt to the dynamic page timeframe.

While being able to change the timeframe dynamically brings a lot of flexibility for showing data over different timeframes in the same tile, it can also mean that some page timeframe settings are not ideal for your intended search:

  • The tile shows no data because the current page timeframe is too short for the fixed time span in your search query. In this case, you can use the page timeframe instead of fixed values in the search query
  • The loading time for the tile is very long because the current page timeframe is too long for the search query. In this case, you can use the page timeframe in the specific timeframe setting to put a cap on the page timeframe that can be used.

Was this article helpful?


Have more questions or facing an issue?