<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dashboards using Real Time Searches in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374622#M39257</link>
    <description>&lt;P&gt;Hello Woodcock, I am getting below out put but unable to correlate. Can you please explain a bit - What it is referring to: &lt;BR /&gt;
disabled                    title                                      eai:acl.app                          eai:appName                             id&lt;BR /&gt;
0             simple_search_realtime    simple_xml_examples                  simple_xml_examples    &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/simple_xml_examples/data/ui/views/simple_search_realtime" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/simple_xml_examples/data/ui/views/simple_search_realtime&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;0           splunk_performance_metrics   em_ss_portal_app            em_ss_portal_app   &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/em_ss_portal_app/data/ui/views/splunk_performance_metrics" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/em_ss_portal_app/data/ui/views/splunk_performance_metrics&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 14:41:29 GMT</pubDate>
    <dc:creator>gagandeep_arora</dc:creator>
    <dc:date>2020-09-29T14:41:29Z</dc:date>
    <item>
      <title>Dashboards using Real Time Searches</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374619#M39254</link>
      <description>&lt;P&gt;I am looking for a search to find what all Dashboards are using Real Time Searches.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 16:07:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374619#M39254</guid>
      <dc:creator>gagandeep_arora</dc:creator>
      <dc:date>2017-06-29T16:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards using Real Time Searches</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374620#M39255</link>
      <description>&lt;P&gt;Hi gagandeep_arora,&lt;BR /&gt;
as my previous answer:&lt;BR /&gt;
use Splunk Distributed Monitoring Console App to monitor your search activity.&lt;BR /&gt;
In addition you could use Search Activity App (&lt;A href="https://splunkbase.splunk.com/app/2632/"&gt;https://splunkbase.splunk.com/app/2632/&lt;/A&gt;) but it isn't so easy to configure.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 16:13:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374620#M39255</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-06-29T16:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards using Real Time Searches</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374621#M39256</link>
      <description>&lt;P&gt;Like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|rest/servicesNS/-/-/data/ui/views
| regex eai:data="&amp;lt;earliest&amp;gt;rt"
| table splunk_server disabled title eai:acl.app eai:appName id
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 29 Jun 2017 20:39:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374621#M39256</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-06-29T20:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards using Real Time Searches</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374622#M39257</link>
      <description>&lt;P&gt;Hello Woodcock, I am getting below out put but unable to correlate. Can you please explain a bit - What it is referring to: &lt;BR /&gt;
disabled                    title                                      eai:acl.app                          eai:appName                             id&lt;BR /&gt;
0             simple_search_realtime    simple_xml_examples                  simple_xml_examples    &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/simple_xml_examples/data/ui/views/simple_search_realtime" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/simple_xml_examples/data/ui/views/simple_search_realtime&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;0           splunk_performance_metrics   em_ss_portal_app            em_ss_portal_app   &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/em_ss_portal_app/data/ui/views/splunk_performance_metrics" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/em_ss_portal_app/data/ui/views/splunk_performance_metrics&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:41:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374622#M39257</guid>
      <dc:creator>gagandeep_arora</dc:creator>
      <dc:date>2020-09-29T14:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards using Real Time Searches</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374623#M39258</link>
      <description>&lt;P&gt;What is there to correlate?  You have the name of the search and the app that it is in.  Just go look at it.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 21:53:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374623#M39258</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-06-29T21:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards using Real Time Searches</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374624#M39259</link>
      <description>&lt;P&gt;Got it, The only confusion was from the applications are coming "&lt;A href="https://127.0.0.1:8089"&gt;https://127.0.0.1:8089&lt;/A&gt;" doesnt make sense to me as I have 4 different Search Head Clustered environment. &lt;/P&gt;

&lt;P&gt;I found the solution, Your query works fine here, I just molded it to get more information relevant to the exact searchhead by using field (splunk_server) in the table.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 14:51:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374624#M39259</guid>
      <dc:creator>gagandeep_arora</dc:creator>
      <dc:date>2017-06-30T14:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards using Real Time Searches</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374625#M39260</link>
      <description>&lt;P&gt;Ah, now I see what you mean; I updated my answer, too.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2019 15:06:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboards-using-Real-Time-Searches/m-p/374625#M39260</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-11-08T15:06:42Z</dc:date>
    </item>
  </channel>
</rss>

