.NET Core microservices on Service Fabric

Video: https://channel9.msdn.com/Events/dotnetConf/2017/T226

Slides: https://photos.app.goo.gl/MtH6hU7iBIf1l1PV2

Advertisements

Splunk Dashboard with Base Search

http://docs.splunk.com/Documentation/Splunk/6.2.5/Viz/Savedsearches#Post-process_searches

basically there is a dashboard with n panels, but all of the panels use the same search just with some differences in its post processing…

This base search is common to all panels using it:

<search id=”baseSearch“>
<query>
index=_internal source=*splunkd.log | stats count by component, log_level
</query>
</search>

<row>
<panel>
<chart>
<title>Event count by log level</title>

<!– post-process search –>
<search base=”baseSearch”>
<query>
stats sum(count) AS count by log_level
</query>
</search>

 

PS: Use |fields * in the base search to force it to run in verbose mode. This is the easiest way to make sure all fields are available to the post processing in Panel Search Queries