<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Top usernames in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Top-usernames/m-p/95453#M6540</link>
    <description>&lt;P&gt;Absolutely.&lt;/P&gt;

&lt;P&gt;First of all, create a saved search that you can use in the dashboard. For reference, the saved search used for the Top 10 IP chart is called "Top 10 client IPs" and is as simple as:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype="squid" action="*" | top 10 clientip
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Second, edit the dashboard XML. It's in the file &lt;CODE&gt;SplunkforSquid/default/data/ui/views/dashboard.xml&lt;/CODE&gt;. In there you'll see a number of a number of sections beginning with HiddenSavedSearch modules. This is the one for the top client IP's:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;module name="HiddenSavedSearch" layoutPanel="panel_row3_col1" group="Top client IPs" autoRun="True"&amp;gt;
  &amp;lt;param name="useHistory"&amp;gt;false&amp;lt;/param&amp;gt;
  &amp;lt;param name="savedSearch"&amp;gt;Top 10 client IPs&amp;lt;/param&amp;gt;
  &amp;lt;module name="EnablePreview"&amp;gt;
   &amp;lt;param name="enable"&amp;gt;true&amp;lt;/param&amp;gt;
   &amp;lt;param name="display"&amp;gt;false&amp;lt;/param&amp;gt;
   &amp;lt;module name="HiddenChartFormatter"&amp;gt;
    &amp;lt;param name="chart"&amp;gt;pie&amp;lt;/param&amp;gt;
    &amp;lt;module name="FlashChart"&amp;gt;
     &amp;lt;param name="height"&amp;gt;300px&amp;lt;/param&amp;gt;
     &amp;lt;module name="ViewRedirectorLink"&amp;gt;
      &amp;lt;param name="viewTarget"&amp;gt;flashtimeline&amp;lt;/param&amp;gt;
      &amp;lt;param name="label"&amp;gt;View full results&amp;lt;/param&amp;gt;
     &amp;lt;/module&amp;gt;
    &amp;lt;/module&amp;gt;
   &amp;lt;/module&amp;gt;
  &amp;lt;/module&amp;gt;
 &amp;lt;/module&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You can either simply change this section and switch the &lt;CODE&gt;savedSearch&lt;/CODE&gt; name for the one you created for getting top usernames (and probably change the &lt;CODE&gt;group&lt;/CODE&gt; name to get the correct label as well), or you can duplicate it if you want both charts in your dashboard. If you duplicate the section, make sure to update the &lt;CODE&gt;layoutPanel&lt;/CODE&gt; to get the chart where you want.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Oct 2011 19:01:18 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2011-10-20T19:01:18Z</dc:date>
    <item>
      <title>Top usernames</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Top-usernames/m-p/95452#M6539</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;How can i add a colum on the traffic dashboard just like Top client IP's, but then with the Top Usernames?&lt;/P&gt;

&lt;P&gt;It may replace one of the other colums, but its not necessary&lt;/P&gt;

&lt;P&gt;Is this possible? If yes, how?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2011 16:07:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Top-usernames/m-p/95452#M6539</guid>
      <dc:creator>ajstokvis</dc:creator>
      <dc:date>2011-10-20T16:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Top usernames</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Top-usernames/m-p/95453#M6540</link>
      <description>&lt;P&gt;Absolutely.&lt;/P&gt;

&lt;P&gt;First of all, create a saved search that you can use in the dashboard. For reference, the saved search used for the Top 10 IP chart is called "Top 10 client IPs" and is as simple as:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype="squid" action="*" | top 10 clientip
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Second, edit the dashboard XML. It's in the file &lt;CODE&gt;SplunkforSquid/default/data/ui/views/dashboard.xml&lt;/CODE&gt;. In there you'll see a number of a number of sections beginning with HiddenSavedSearch modules. This is the one for the top client IP's:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;module name="HiddenSavedSearch" layoutPanel="panel_row3_col1" group="Top client IPs" autoRun="True"&amp;gt;
  &amp;lt;param name="useHistory"&amp;gt;false&amp;lt;/param&amp;gt;
  &amp;lt;param name="savedSearch"&amp;gt;Top 10 client IPs&amp;lt;/param&amp;gt;
  &amp;lt;module name="EnablePreview"&amp;gt;
   &amp;lt;param name="enable"&amp;gt;true&amp;lt;/param&amp;gt;
   &amp;lt;param name="display"&amp;gt;false&amp;lt;/param&amp;gt;
   &amp;lt;module name="HiddenChartFormatter"&amp;gt;
    &amp;lt;param name="chart"&amp;gt;pie&amp;lt;/param&amp;gt;
    &amp;lt;module name="FlashChart"&amp;gt;
     &amp;lt;param name="height"&amp;gt;300px&amp;lt;/param&amp;gt;
     &amp;lt;module name="ViewRedirectorLink"&amp;gt;
      &amp;lt;param name="viewTarget"&amp;gt;flashtimeline&amp;lt;/param&amp;gt;
      &amp;lt;param name="label"&amp;gt;View full results&amp;lt;/param&amp;gt;
     &amp;lt;/module&amp;gt;
    &amp;lt;/module&amp;gt;
   &amp;lt;/module&amp;gt;
  &amp;lt;/module&amp;gt;
 &amp;lt;/module&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You can either simply change this section and switch the &lt;CODE&gt;savedSearch&lt;/CODE&gt; name for the one you created for getting top usernames (and probably change the &lt;CODE&gt;group&lt;/CODE&gt; name to get the correct label as well), or you can duplicate it if you want both charts in your dashboard. If you duplicate the section, make sure to update the &lt;CODE&gt;layoutPanel&lt;/CODE&gt; to get the chart where you want.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2011 19:01:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Top-usernames/m-p/95453#M6540</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-10-20T19:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Top usernames</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Top-usernames/m-p/95454#M6541</link>
      <description>&lt;P&gt;Thank you very much!!&lt;BR /&gt;
It works realy nice.&lt;/P&gt;

&lt;P&gt;I have another question, is it possible to filter out one user?&lt;/P&gt;

&lt;P&gt;I have 1 user that i dont want to see in the chart.&lt;BR /&gt;
Can i make an exception for that user so that it dont show up in the chart?&lt;/P&gt;

&lt;P&gt;Thank you very much for this, splunkforsquid is what i have been looking for a long time!!!&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2011 13:53:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Top-usernames/m-p/95454#M6541</guid>
      <dc:creator>ajstokvis</dc:creator>
      <dc:date>2011-10-24T13:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: Top usernames</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Top-usernames/m-p/95455#M6542</link>
      <description>&lt;P&gt;Sure, just filter out the user in your saved search. Something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; search = sourcetype="squid" action="*" NOT username="theuser" | top 10 username
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Great to hear that it's working and that it's useful! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
Could you please mark my answer as accepted? That way it shows clearly on the site that this question got a valid answer.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2011 14:02:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Top-usernames/m-p/95455#M6542</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-10-24T14:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Top usernames</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Top-usernames/m-p/95456#M6543</link>
      <description>&lt;P&gt;Works again!!!&lt;/P&gt;

&lt;P&gt;I might come with more questions in the future! &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Realy happy with this&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2011 14:09:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Top-usernames/m-p/95456#M6543</guid>
      <dc:creator>ajstokvis</dc:creator>
      <dc:date>2011-10-24T14:09:38Z</dc:date>
    </item>
  </channel>
</rss>

