If you're anything our team at Function1, you can't wait to experiment with all of Splunk 7's dynamic new features. One of these features is “Event Annotations,” a powerful tool to highlight charts. At the moment, Event Annotations can be used in time-series charts. They are relatively simple to use; all you need is a separate search on your dashboard of type=annotation, with the annotation_label defined as the field you want to show as an annotation, and the annotation_category defined as the field to group your annotations by type. There is a simple but comprehensive example in the...
Splunk 7 Event Annotations and You!
Posted by Alex Wade
on Tuesday, October 24, 2017 - 10:19
Operational Intelligence Splunk 7.0, Cool Tools, Splunk, New Features, Event Annotation, Annotation