<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Make set of data easily searchable for users on a dashboard? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Make-set-of-data-easily-searchable-for-users-on-a-dashboard/m-p/352439#M22955</link>
    <description>&lt;P&gt;Hi xxkenta,&lt;BR /&gt;
I usually create an App for each destination, I like this approach to have in one App all the knowledge objects (fields, tags, etc...) related to that problem.&lt;BR /&gt;
In this case you'll have an App with at least one dashboard.&lt;/P&gt;

&lt;P&gt;If I correctly undestood your need, we solved a similar problem creating an App (called Log Analyzer) used by developers that didn't know Splunk to debug their applications logs.&lt;BR /&gt;
We have many logs and many flows, so we created a dashboard with some filters to identify the log flow to analyze (e.g. using sourcetype or source or host), in addition there's a text box to perform free text searches.&lt;BR /&gt;
Result is _raw.&lt;/P&gt;

&lt;P&gt;After I developed some dashboard to monitor inputs and understand volumes, perimeter, etc...&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 19 Dec 2017 07:48:58 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2017-12-19T07:48:58Z</dc:date>
    <item>
      <title>Make set of data easily searchable for users on a dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Make-set-of-data-easily-searchable-for-users-on-a-dashboard/m-p/352437#M22953</link>
      <description>&lt;P&gt;I would like to make either an app/add-on or a dashboard so that users who use Splunk only for a specific set of logs can search that data easier. &lt;/P&gt;

&lt;P&gt;I would like them to be able to select said app or dashboard and then enter in search data. Currently, the particular data is coming in from the same index as a lot of other data, and the users have to remember to search for a particular field, &lt;STRONG&gt;"process=&lt;EM&gt;a_process&lt;/EM&gt;"&lt;/STRONG&gt;, in order for the rest of their data (ip address or username) to show relevant search data.&lt;/P&gt;

&lt;P&gt;Which would be better for this case between an &lt;STRONG&gt;app or a dashboard&lt;/STRONG&gt;? How can I configure it so that they do not need to enter in &lt;BR /&gt;
this field for them to search for related data? Eventually graphs and visualizations will be added to the page.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2017 21:22:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Make-set-of-data-easily-searchable-for-users-on-a-dashboard/m-p/352437#M22953</guid>
      <dc:creator>xxkenta</dc:creator>
      <dc:date>2017-12-18T21:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Make set of data easily searchable for users on a dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Make-set-of-data-easily-searchable-for-users-on-a-dashboard/m-p/352438#M22954</link>
      <description>&lt;P&gt;seems like a good use case for "tags"&lt;BR /&gt;
read here:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.1/Knowledge/Abouttagsandaliases"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.1/Knowledge/Abouttagsandaliases&lt;/A&gt;&lt;BR /&gt;
hope it helps&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2017 02:33:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Make-set-of-data-easily-searchable-for-users-on-a-dashboard/m-p/352438#M22954</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-12-19T02:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: Make set of data easily searchable for users on a dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Make-set-of-data-easily-searchable-for-users-on-a-dashboard/m-p/352439#M22955</link>
      <description>&lt;P&gt;Hi xxkenta,&lt;BR /&gt;
I usually create an App for each destination, I like this approach to have in one App all the knowledge objects (fields, tags, etc...) related to that problem.&lt;BR /&gt;
In this case you'll have an App with at least one dashboard.&lt;/P&gt;

&lt;P&gt;If I correctly undestood your need, we solved a similar problem creating an App (called Log Analyzer) used by developers that didn't know Splunk to debug their applications logs.&lt;BR /&gt;
We have many logs and many flows, so we created a dashboard with some filters to identify the log flow to analyze (e.g. using sourcetype or source or host), in addition there's a text box to perform free text searches.&lt;BR /&gt;
Result is _raw.&lt;/P&gt;

&lt;P&gt;After I developed some dashboard to monitor inputs and understand volumes, perimeter, etc...&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2017 07:48:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Make-set-of-data-easily-searchable-for-users-on-a-dashboard/m-p/352439#M22955</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-12-19T07:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Make set of data easily searchable for users on a dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Make-set-of-data-easily-searchable-for-users-on-a-dashboard/m-p/352440#M22956</link>
      <description>&lt;P&gt;Thank you. If I create an app for this, say a user wants to debug something related to an IP address 10.10.10.10. Normally they'd have to search "process=a_process 10.10.10.10". How would I configure the app to assume this "process=a_process" so that the user only needs to search the ip address?&lt;/P&gt;

&lt;P&gt;Thank you &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:19:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Make-set-of-data-easily-searchable-for-users-on-a-dashboard/m-p/352440#M22956</guid>
      <dc:creator>xxkenta</dc:creator>
      <dc:date>2020-09-29T17:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Make set of data easily searchable for users on a dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Make-set-of-data-easily-searchable-for-users-on-a-dashboard/m-p/352441#M22957</link>
      <description>&lt;P&gt;Thank you. If I create an app for this, say a user wants to debug something related to an IP address 10.10.10.10. Normally they'd have to search "process=a_process 10.10.10.10". How would I configure the app to assume this "process=a_process" so that the user only needs to search the ip address?&lt;/P&gt;

&lt;P&gt;Thank you &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:19:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Make-set-of-data-easily-searchable-for-users-on-a-dashboard/m-p/352441#M22957</guid>
      <dc:creator>xxkenta</dc:creator>
      <dc:date>2020-09-29T17:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Make set of data easily searchable for users on a dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Make-set-of-data-easily-searchable-for-users-on-a-dashboard/m-p/352442#M22958</link>
      <description>&lt;P&gt;Hi xxkenta,&lt;/P&gt;

&lt;P&gt;if your conditions are fixed you can use a fixed search, something like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=your_index process=a_process 10.10.10.10
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and display _row.&lt;/P&gt;

&lt;P&gt;If instead you want to choose different conditions, create one or more lookups for your conditions (e.g. processes.csv and perimeter.csv), and use one or more filters, e.g. a dropdown for process field and a dropdown for IPs, then in your search use something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=your_index process=$process$ IP=$IP$
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;where process and IP are two tokens from two dropdowns.&lt;/P&gt;

&lt;P&gt;Anyway insert always a text box for free text searches, is very useful!&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 08:00:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Make-set-of-data-easily-searchable-for-users-on-a-dashboard/m-p/352442#M22958</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-12-20T08:00:55Z</dc:date>
    </item>
  </channel>
</rss>

