# Kibana dashboard

**URL:** <https://discuss.elastic.co/t/kibana-dashboard/259983>\
**Category:** Kibana\
**Created:** [January 1, 2021, 7:41am UTC](https://discuss.elastic.co/t/kibana-dashboard/259983 "2021-01-01T07:41:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sajal](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@Sajal](https://discuss.elastic.co/u/Sajal)\
**Post date:** [January 1, 2021, 7:41am UTC](https://discuss.elastic.co/t/kibana-dashboard/259983/1 "2021-01-01T07:41:11Z")

</div>

Hi Folks ,

Can you please help me to make Kibana dashboard . I have got below Splunk Query from which i need to make Kibana Dashboard. We are migrating from Splunk to ELK.  
How to create deviation and and use in where clause ?

index=digital sourcetype=channel-services EntryExitLog country=US earliest=-65m latest=-5m AND NOT (ChannelErrorCode=C1131 OR ChannelErrorCode=C5241 OR ChannelErrorCode=C5242 OR ChannelErrorCode=C6006 OR ChannelErrorCode=C6017 OR ChannelErrorCode=C3579 OR ChannelErrorCode=C1999 OR ChannelErrorCode=C1052 OR ChannelErrorCode=C1266 OR ChannelErrorCode=C1462 OR ChannelErrorCode=C1620 OR ChannelErrorCode=C1974 OR ChannelErrorCode=C7799 OR ChannelErrorCode=C6007 OR ChannelErrorCode=C1787 OR ChannelErrorCode=C1068 OR ChannelErrorCode=C1121 OR ChannelErrorCode=C1124 OR ChannelErrorCode=C1775 OR ChannelErrorCode=C2012 OR ChannelErrorCode=C5000 OR ChannelErrorCode=C6518 OR ChannelErrorCode=C8021 OR ChannelErrorCode=C8112)| stats dc(ChannelSessionId) as CWC by ChannelErrorCode  
|join type=outer ChannelErrorCode [ search index=digital

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/f/cf2506a857f89331cfd8435083e31a5ce0304d78.png) sourcetype=channel-services country=US EntryExitLog earliest=-20225m latest=-20165m | stats dc(ChannelSessionId) as LFC by ChannelErrorCode] | fillnull value=0  
| eval deviation=round(((CWC-LFC)\*100/LFC),0)  
| where (LFC=0 AND CWC\>7) OR (LFC\<6 AND deviation\>500) OR (LFC\>5 AND LFC\<15 AND deviation\>300) OR (LFC\>=15 AND LFC\<30 AND deviation\>200) OR (LFC\>=30 AND LFC\<50 AND deviation\>100) OR (LFC\>=50 AND LFC\<100 AND deviation\>50) OR (LFC\>=100 AND deviation\>20)

Attached Splunk dashboard which i need to make in Kibana .

Thanks  
Sajal

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 2, 2021, 1:53am UTC](https://discuss.elastic.co/t/kibana-dashboard/259983/2 "2021-01-02T01:53:43Z")

</div>

What have you tried so far?

---

<div class="post-metadata">

**Author:** ![Sajal](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@Sajal](https://discuss.elastic.co/u/Sajal)\
**Post date:** [January 4, 2021, 9:36am UTC](https://discuss.elastic.co/t/kibana-dashboard/259983/3 "2021-01-04T09:36:56Z")

</div>

Hi warkolm,

i am able to get count of below query bit how should i get deviation ?

index=digital sourcetype=channel-services EntryExitLog country=US earliest=-65m latest=-5m AND NOT (ChannelErrorCode=C1131 OR ChannelErrorCode=C5241 OR ChannelErrorCode=C5242 OR ChannelErrorCode=C6006 OR ChannelErrorCode=C6017 OR ChannelErrorCode=C3579 OR ChannelErrorCode=C1999 OR ChannelErrorCode=C1052 OR ChannelErrorCode=C1266 OR ChannelErrorCode=C1462 OR ChannelErrorCode=C1620 OR ChannelErrorCode=C1974 OR ChannelErrorCode=C7799 OR ChannelErrorCode=C6007 OR ChannelErrorCode=C1787 OR ChannelErrorCode=C1068 OR ChannelErrorCode=C1121 OR ChannelErrorCode=C1124 OR ChannelErrorCode=C1775 OR ChannelErrorCode=C2012 OR ChannelErrorCode=C5000 OR ChannelErrorCode=C6518 OR ChannelErrorCode=C8021 OR ChannelErrorCode=C8112)| stats dc(ChannelSessionId) as CWC by ChannelErrorCode

Thanks  
Sajal

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2021, 9:37am UTC](https://discuss.elastic.co/t/kibana-dashboard/259983/4 "2021-02-01T09:37:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
