icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Covid19 Reporting
SHA256 checksum (covid19-reporting_076.tgz) 8cddaf5f0022aefc4487879be4f6d753d6ab3bfb5fde60586f9aeaf5db01b96c SHA256 checksum (covid19-reporting_075.tgz) 7001fcd756a83d166de255204379ffedb6d69808f28644a205115afc6419f8cd SHA256 checksum (covid19-reporting_074.tgz) af3b7ccfe9df340f47bb006e238e41a1fb00a9167adf96668cebfbab9c2b09f0 SHA256 checksum (covid19-reporting_073.tgz) 45d3882621135c8ca35abb7d74b074d842ba86ffe1f4d68ef2630a9a7b59e8d6 SHA256 checksum (covid19-reporting_072.tgz) 95af4c2a9782142acf46e7902fad5357d6c131e9daa3d770798274b0f1007d2f SHA256 checksum (covid19-reporting_071.tgz) 98b3a6e713c32435dd0de261987d4a2fe5a90d4a42a50d5ab00f4100f37b3cca SHA256 checksum (covid19-reporting_07.tgz) 00997b70f06efaf9006aa4537370392d22b368c447616007911bcc194cfd5170 SHA256 checksum (covid19-reporting_06.tgz) d48924de69ee42080ff9a5921d4b7724702e14101f4f3afc25d1f785f346c44f SHA256 checksum (covid19-reporting_052.tgz) 7be29810da358025cc253df4ecc0497ca3747c7ac2fe2d5aef145c7b803dde7c SHA256 checksum (covid19-reporting_051.tgz) 5268be4aaf6d84b3adf1a0b2924c91ea672f36899000faa302be5b2bac024967 SHA256 checksum (covid19-reporting_05.tgz) 92ba76f53b050d38af17ccf906b373d8fd54f9e62ef15f489be0bcaf3e419400 SHA256 checksum (covid19-reporting_043.tgz) 561fd2dd714c699c8fa3bbac6f40302030893e383d25fd014060a8d036d5d1af SHA256 checksum (covid19-reporting_042.tgz) 44c408e052ec9335cc19782f6b3078c65994522472c0f884e4235748669c3233 SHA256 checksum (covid19-reporting_041.tgz) 9dd32389828efa3a5dfb21994523e08e5ba657f91e020dafad9ddc9fc80b444b SHA256 checksum (covid19-reporting_04.tgz) 36cdbc0fd81213affb84793884ad65349dd7209d50c3112c7618edabab795165 SHA256 checksum (covid19-reporting_034.tgz) 604916c68557d27f8aa3bcde8db9b3925a53c45a6ca83d5dd18f33ffdc75d80c SHA256 checksum (covid19-reporting_033.tgz) dd84378cb53aa4cdd1f4b2e296d426708baa08c31c24746fda1375971faeaa23 SHA256 checksum (covid19-reporting_032.tgz) 46830c7196dfe108ec0f318c1cf67254f0a38a49747dc665d943ee3bc868ed32 SHA256 checksum (covid19-reporting_024.tgz) b18a49ff58fd046236e80806ab000999ea2c27b887ab548400f96f6c551d3c18 SHA256 checksum (covid19-reporting_02.tgz) 330279c3d35dde5f300803d22133d065e0c6eee9ec6f98c42a1a523c0c6a71f4
To install your download
For instructions specific to your download, click the Details tab after closing this window.
To install apps and add-ons from within Splunk Enterprise
  1. Log into Splunk Enterprise.
  2. On the Apps menu, click Manage Apps.
  3. Click Install app from file.
  4. In the Upload app window, click Choose File.
  5. Locate the .tar.gz file you just downloaded, and then click Open or Choose.
  6. Click Upload.
  7. Click Restart Splunk, and then confirm that you want to restart.
To install apps and add-ons directly into Splunk Enterprise
  1. Put the downloaded file in the $SPLUNK_HOME/etc/apps directory.
  2. Untar and ungzip your app or add-on, using a tool like tar -xvf (on *nix) or WinZip (on Windows).
  3. Restart Splunk.
After you install a Splunk app, you will find it on Splunk Home. If you have questions or need more information, see Manage app and add-on objects.

Flag As Inappropriate

Covid19 Reporting

Admins: Please read about Splunk Enterprise 8.0 and the Python 2.7 end-of-life changes and impact on apps and upgradeshere.
This app is updated at least once per day. It contains a snapshot of the latest data from Johns Hopkins University's CSSE group's Covid19 page. ( https://github.com/CSSEGISandData/COVID-19/tree/master/csse_covid_19_data ). The app also ships an index to put the data in, and an enabled data input that will index it. The end result is that a minute or so after installation you will be able to fully use the entire app.

NOTE - You will first need to install the "Canary" app and the "Sideview Utils" app, also from Splunkbase.

This app's focus is allowing anyone to keep up to date of the exponential development of the Covid19 pandemic. You choose which countries you are interested in, or for a particular country you can choose which states/provinces you're interested in. You then chart various statistics over time.

One of the app's most important features is that you can switch between a logarithmic Y-axis and a normal (linear) Y-axis. Many of the charts default to logarithmic Y-axis, as do many of the screenshots above.

For all of you who may not recall your high school math as well as you would like, here is a quick primer.

1) Any exponential curve means in a nutshell that there is a "doubling time" for the underlying trend.

2) It is very difficult for the human eye to interpret multiple exponential curves on a linear axis. It generally always looks like "the biggest one or two are where all the problems are", and the chart tends to look strangely identical every day but with startling changes to the numbers on the y-axis.

3) However If you have lines following exponential curves and you chart them on a logarithmic Y-axis instead (ie if you make the evenly spaced tick marks be 10, 100, 1000, 10000 instead of 0,500,1000,1500) then the lines become straight and the human eye can easily extrapolate them.
The slope or steepness of each straight line then corresponds visually to that "doubling time".

4) Conversely, if you put lines on a logarithmic axis and they become quite straight, that means the trend, whatever it is, is still behaving like an unrestrained exponential curve. It also means that while the curve might "flatten" soon, it's not doing it yet.

-- Italy's number of "current confirmed or testing positive" patients is doubling about every 6 days.
-- California's is doubling about every 3 days.
-- New York's is doubling about every 2 days (as of this writing 3/21/2020).

However you may not have noticed yet that MANY states have doubling rates in 2-3 days.
-- Louisiana, Florida, Michigan, Colorado, Georgia, Massachusetts etc...
-- Since the raw numbers of these other states are much lower they're not in the news as much yet.

NOTE - if you prefer docker, with HUGE thanks to Clint Sharp, is the docker alternative to install all the things at once.
docker run -p 8000:8000 -it clintsharp/sideview_covid:latest

Release Notes

Version 0.7.6
March 30, 2020

- Added some higher numbers to the "by number of days since the" selector. Unfortunately it is sometimes useful to normalize the x-axis to these much higher numbers now.
- Moved the layer of reset links into its own Pattern file.
- Added a new prototype that allows the same sort of interactivity but specifically for the counties within one particular US State. For all non-US users out there, unfortunately the JHU dataset recently started providing this County-level detail only for US States. For what it's worth when similar granularity is available for other countries I will certainly try and expose that as additional functionality, as I've done here for the US.)
- (New data for 3/29 loaded from JHU CSSE)

Version 0.7.5
March 29, 2020

- Added a disclaimer to both "cases over time by country or state" and "recovery by country" to call out that the "Recovered" numbers in the dataset are not broken out by US State. Without this disclaimer it seemed potentially quite alarming. Hopefully the JHU CSSE folks are able to soon break this down by state and I can change this disclaimer or remove it later.
- (New data for 3/28 loaded from JHU CSSE)

Version 0.7.4
March 28, 2020

(New data for 3/27 loaded from JHU CSSE)

Version 0.7.3
March 27, 2020

- Fixed a misconfiguration of the main view, where the main Country/Province/State pulldown would reset to the default every time you reloaded the page (rather than using the selection preserved in the url)
- minor fix so the chart doesn't redispatch when you just change the y-axis type.
- Expanded the 'reset to default' link to also allow you to reset to selecting all the provinces within the few countries that have that level of granularity. This is only a convenience but it saves a lot of time selecting/deselecting provinces and states.
- Also I have added another static lookup to handle normalization of various Province_State names that have typos or inconsistencies.
- (data for 3/26 loaded from JHU CSSE)

Version 0.7.2
March 27, 2020

- Fixed a minor bug where the explanatory note above the main chart always said the xaxis showed days since the Nth "confirmed case", even when that option was set to 'deaths' instead.
- (New data for the past day loaded from JHU CSSE)

Version 0.7.1
March 26, 2020

quick fix for a regression in the 0.7 build just posted, where 'recovery-over-time' tab didn't load.

Version 0.7
March 26, 2020

Splunkbase restricts release notes to only 1000 characters and the notes for this release exceed that number.

However for complete release notes for this and all releases, you can always refer to our website.


Version 0.6
March 25, 2020

- Improved the `get_count_of_days_since_nth_case` further, so now it can take three optional args. See comments in macros.conf
- Added the ability to explode out the countries/provinces and treat them as separate countries. This allows a much more flexible analysis - notably you can compare individual US states or Australian or Canadian provinces to entire countries. The previous tab doing per-state analysis has been deleted.
- Added controls to allow the user to change from the x-axis being "days since the 100th confirmed case" from 100 to any N, and from "confirmed case" to "death".
- Fixed a bug where clicking 'see raw search syntax' on a tabular output would dump you out into a column chart
- Pulled out the primer on logarithmic y-axes into its own page under 'notes'
- Upped the required version of Canary to 1.2.3, and added a little message that appears in the top of the analysis view, if the version is too low

Version 0.5.2
March 24, 2020

Fixed a problem in the "COVID-19 dataset" tab where the covidtracking.com data rows were appearing there, but with most columns blank. As this was confusing and served no purpose I filtered them out
Fixed a regression in the "COVID-19 dataset" tab where the selection of the province/state element had no effect on the results.
Added some text underneath the main tab giving users a primer on exponential curves and how to interpret charts with logarithmic y-axes
Since the JHU CSSE data suddenly has a whole other field for US County, but the field name strangely is "Admin2", I've renamed the field to "County" and made it visible in the Covid19 tab.

Version 0.5.1
March 23, 2020

Fixed an unfortunately bug that only happened on 7.3, but that prevented users from being redirected into the app correctly. Instead they were stranded on a page telling them that "TopNav" and "AppNav" modules didnt exist.

Version 0.5
March 23, 2020

Reviewed and made improvements to how we handle days with missing data at the country and province level. Previously the SPL screened out the duplicate records where the "Last Update" referred to a day before the day-based filename the record was in. Now we let those records get indexed and returned at search time but at search time we override the _time value from the filename. Normally this is a bad practice in Splunk and it's better to set it from the filename at index time with INGEST_EVAL. However here it's quick, its effective and we pull the entire set off disk anyway with each search so there's not much of a downside. Also INGEST_EVAL would force reindexing for all upgrades to this release.

Version 0.4.3
March 22, 2020

Removing the warning message added in 0.4.2 and the app now simply dedups the data explicitly on search.
There is a new health checks page, whereby the app ships stanzas in checklist.conf that get run explicitly on this page. Note the checklist.conf stanzas will also run in the Splunk Monitoring Console if any splunk admins are looking there
(New data loaded from JHU CSSE dataset)

Version 0.4.2
March 21, 2020

JHU recently went back and changed something in the daily data from 2 days ago, which is great. However this comes before I had completed the health check to automatically detect this and bubble up a warning to the user

So this release just has a hardcoded warning at the top to always reindex the data after updating to a new version.

Version 0.4.1
March 21, 2020

Redoing the default country selection. The short version is "I added Switzerland".
The Long version - Previously it was the top 10 total confirmed cases, plus an extra 2 - Hong Kong and Singapore which are low but have extremely interesting curves. New it is the top 10, plus an extra 3 - Japan, Hong Kong and Singapore.

Version 0.4
March 21, 2020

the app now ships a snapshot of the per-day testing data for US States from https://covidtracking.com/api/

some key numbers from the us testing data can now be chosen as y-axis values on the per-province/state chart, although of course they only work for US states at the moment.

In the "by province/state" tab I have marked the "Recovered" yaxis option as "(doesn't work with recent US data)", The reason is that since the "Recovered" numbers in the US are no longer associated with individual states, this means we can't really graph that number in the US split by state. While you might think we can create a fake state called 'unknown', we'd ahve to also determine "on what day the unknown state passed 30th confirmed cases" and that's nonsensical.

Version 0.3.4
March 20, 2020

Altered the app so that even if the user fails to install the Sideview Utils app or the Canary app (or both) this app itself will explain that problem to them on the landing page and give them instructions for how to install the missing apps. (Before this version the app would just load a blank page and leave the user stranded.)

Tested on Splunk 7.3 and since everything seems fine, I am marking it compatible with 7.3 (prior to this it was marked in SB as Splunk 8.X only)

gave the navigation bar a link to the release notes file.

Version 0.3.3
March 20, 2020

- (New data loaded from JHU CSSE dataset. I try to push a new build asap when there's new data on github)

Version 0.3.2
March 19, 2020

unfortunately Splunkbase truncates release notes at only 1000 characters so our notes for this release do not fit in this field.

However you can read the release notes for this release as well as all others over on our website - https://sideviewapps.com/apps/covid19-reporting/release-notes/

Version 0.2.4
March 18, 2020

(i need to backfill release notes but right now since it's still been languishing many days in the SB manual review queue, it's not a pressing task)

Version 0.2
March 16, 2020

Development of this app began on March 14th and is proceeding quite rapidly. I plan on posting daily updates, as this app actually has a current snapshot of the CSSE COVID19 dataset contained inside it.

Once you install the app and restart Splunk, the app will create a new index called "covid19" and index the daily_report data (a copy of which ships within the app itself) into that index.

Check back soon for updates. Email nick@sideviewapps.com with any questions/comments.


Subscribe Share

AppInspect Tooling

Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2020 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.