Splunk新手求助:如何优化值班人员仪表盘的数据过滤与展示
Splunk值班人员仪表盘问题修复方案
问题概述
- 背景:Splunk新手,需制作值班人员仪表盘,展示用户名、联系方式、OnCallStart、OnCallEnd
- 当前问题:
team列无法正常显示- 查询结果存在大量空行
- 组织多选框过滤无效,仍显示无关内容
- 额外需求:
- 用户归属多组织时,仅展示对应组织的关联信息
- 值班时间与组织/团队关联,以单行形式展示
- 已尝试无效方法:
|head 1、props.conf的TRUNCATE配置、源码限制
当前使用的SPL
index=blahblah-oncall sourcetype=blahblahschedule | spath org | search org=* | spath "teams{}.schedules{}.schedule{}.onCallUser.username" | search "teams{}.schedules{}.schedule{}.onCallUser.username"=* | spath "teams{}.team.name" | search "teams{}.team.name"=* | rename "teams{}.schedules{}.schedule{}.onCallUser.username" as Username | table Username, org,team, OnCallStart, OnCallEnd | append [search index=blahblah-oncall sourcetype=blahblahschedule | spath "teams{}.schedules{}.schedule{}.onCallUser.username" | search "teams{}.schedules{}.schedule{}.onCallUser.username"=* | spath "teams{}.schedules{}.schedule{}.rolls{}.end" | search "teams{}.schedules{}.schedule{}.rolls{}.end"=* | rename "teams{}.schedules{}.schedule{}.rolls{}.end" as OnCallEnd | rename "teams{}.schedules{}.schedule{}.onCallUser.username" as Username | table Username, org,team, OnCallStart, OnCallEnd] | stats values(*) as * by Username | append [search index=blahblah-oncall sourcetype=blahblahschedule | spath "teams{}.schedules{}.schedule{}.onCallUser.username" | search "teams{}.schedules{}.schedule{}.onCallUser.username"=* | spath "teams{}.schedules{}.schedule{}.rolls{}.start" | search "teams{}.schedules{}.schedule{}.rolls{}.start"=* | rename "teams{}.schedules{}.schedule{}.rolls{}.start" as OnCallStart | rename "teams{}.schedules{}.schedule{}.onCallUser.username" as Username | table Username, org,team, OnCallStart, OnCallEnd] | stats values(*) as * by Username | append [search index=blahblah-oncall sourcetype=blahblahschedule | spath "teams{}.schedules{}.schedule{}.onCallUser.username" | search "teams{}.schedules{}.schedule{}.onCallUser.username"=* | spath "teams{}.schedules{}.schedule{}.rolls{}.end" | search "teams{}.schedules{}.schedule{}.rolls{}.end"=* | rename "teams{}.schedules{}.schedule{}.rolls{}.end" as OnCallEnd | rename "teams{}.schedules{}.schedule{}.onCallUser.username" as Username | table Username, org,team, OnCallStart, OnCallEnd] | stats values(*) as * by Username | stats values(*) as * by Username | table org,team, Username, OnCallStart, OnCallEnd | search $orgs$ | sort org
问题根源分析
- 重复
append子查询导致数据关联断裂,team、org与时间字段无法正确匹配 - 未处理JSON嵌套数组(
teams{}、schedules{}),多值字段未展开,导致空行和字段缺失 - 多次
stats values(*) as * by Username破坏了组织、团队与值班时间的关联关系 - 组织过滤时机过晚,无效数据已参与聚合,导致过滤失效
优化后的SPL
index=blahblah-oncall sourcetype=blahblahschedule | spath output=org path=org # 明确提取顶层org字段 | spath output=team_name path="teams{}.team.name" # 提取团队名称 | spath output=username path="teams{}.schedules{}.schedule{}.onCallUser.username" # 提取值班用户名 | spath output=oncall_start path="teams{}.schedules{}.schedule{}.rolls{}.start" # 提取值班开始时间 | spath output=oncall_end path="teams{}.schedules{}.schedule{}.rolls{}.end" # 提取值班结束时间 | mvexpand team_name username oncall_start oncall_end # 展开所有嵌套数组,生成独立的组织-团队-用户-时间行 | where isnotnull(org) AND isnotnull(team_name) AND isnotnull(username) AND isnotnull(oncall_start) AND isnotnull(oncall_end) # 过滤所有空值记录,消除空行 | rename username as Username, team_name as team, oncall_start as OnCallStart, oncall_end as OnCallEnd # 重命名为目标字段名 | search $orgs$ # 提前过滤组织,减少计算量并确保过滤有效 | table org, team, Username, OnCallStart, OnCallEnd # 整理目标字段 | sort org, team # 按组织、团队排序
优化说明
- 用
spath output=xxx path=xxx明确指定字段提取路径,避免多值字段混乱 mvexpand展开嵌套数组,确保每个值班记录(组织-团队-用户-时间)为单行,解决字段不关联问题where直接过滤空值,彻底消除空行- 提前执行组织过滤,避免无效数据进入后续流程,解决过滤失效问题
- 移除冗余的
append和stats操作,保持数据原生关联关系,确保team字段正常显示
内容的提问来源于stack exchange,提问作者Lux-Spawne
相关产品推荐
相关产品推荐

