Splunk search for Most viewed dashboards

Copy
index="_internal" source=*access.log user!="-" */app/* | rex field=_raw "/en-US/app/(?<app>[^/]+)/(?<dashboard>[^?/\s]+)\sHTTP" | stats count by dashboard, app | rename dashboard as "Dashboard Title", app as "App", count as Visits | sort - Visits | head 10
This Splunk search will provide a table showing the 10 most viewed dashboards within your Splunk environment. The search will return the title of the dashboard, what app it belongs to, and a count of how many times it has been visited during the search timeframe.
0 comments

Category:

General Splunk


Tags:

Admin general internal dashboard

Search Commands:

Sign in or Register to submit a comment