<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: adding columns to dashboard queries in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567401#M46598</link>
    <description>&lt;P&gt;in an attempt to be a bit clearer about what I'm looking for. I'm looking for something like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;| time | kubernetes_container_name | log message |&lt;/P&gt;&lt;P&gt;| &lt;SPAN class="t"&gt;2021-09-11&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;21:05:15.590&lt;/SPAN&gt; | contract-mgmt |&amp;nbsp;&lt;SPAN class="t"&gt;2021-09-11&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;21:05:15.590&lt;/SPAN&gt; &lt;SPAN class="t"&gt;INFO&lt;/SPAN&gt; &lt;SPAN class="t"&gt;7&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; [ &lt;/SPAN&gt;&lt;SPAN class="t"&gt;main&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;c.e.h.base.Application&lt;/SPAN&gt; &lt;SPAN class="t"&gt;:&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;Starting&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Application&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;v2.3.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;using&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Java&lt;/SPAN&gt; &lt;SPAN class="t"&gt;11.0.10 |&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;| &lt;SPAN class="t"&gt;2021-09-10&lt;/SPAN&gt; &lt;SPAN class="t"&gt;20:05:15.590&lt;/SPAN&gt; | base-data-mgmt |&amp;nbsp;&lt;SPAN class="t"&gt;2021-09-10&lt;/SPAN&gt; &lt;SPAN class="t"&gt;20:05:15.590&lt;/SPAN&gt; &lt;SPAN class="t"&gt;INFO&lt;/SPAN&gt; &lt;SPAN class="t"&gt;7&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; [ &lt;/SPAN&gt;&lt;SPAN class="t"&gt;main&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;c.e.h.contract.Application&lt;/SPAN&gt; &lt;SPAN class="t"&gt;:&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;Starting&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Application&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;v1.4.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;using&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Java&lt;/SPAN&gt; &lt;SPAN class="t"&gt;11.0.10 |&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Sep 2021 11:53:18 GMT</pubDate>
    <dc:creator>drabbit</dc:creator>
    <dc:date>2021-09-17T11:53:18Z</dc:date>
    <item>
      <title>adding columns to dashboard queries</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567275#M46589</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm trying to make a dashboard element that shows when one of our applications is restarted. So I have&amp;nbsp; a query that searches for "Starting Application". When I put this on my dashboard, I see the columns "i", timestamp, event. How can I add column that shows the kubernetes_container_name? And how can I change column width and trim the original text so I get no line breaks?&lt;/P&gt;&lt;P&gt;thanks for your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 15:13:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567275#M46589</guid>
      <dc:creator>drabbit</dc:creator>
      <dc:date>2021-09-16T15:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: adding columns to dashboard queries</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567299#M46591</link>
      <description>&lt;P&gt;It would help if you shared the query the dashboard uses.&lt;/P&gt;&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;table&lt;/FONT&gt; command specifies the columns the dashboard should display.&amp;nbsp; If it includes "Starting Application" then that column will be present even if the search does not find it.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 17:24:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567299#M46591</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-09-16T17:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: adding columns to dashboard queries</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567400#M46597</link>
      <description>&lt;P&gt;sorry, I thought I had posted it. The query looks like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;"Starting Application" kubernetes_cluster="prod-cluster"&lt;/LI-CODE&gt;&lt;P&gt;and I don't understand what you are referring to as "that column" in your answer. I want the&amp;nbsp;&lt;SPAN&gt;kubernetes_container_name field as a column.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 11:45:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567400#M46597</guid>
      <dc:creator>drabbit</dc:creator>
      <dc:date>2021-09-17T11:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: adding columns to dashboard queries</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567401#M46598</link>
      <description>&lt;P&gt;in an attempt to be a bit clearer about what I'm looking for. I'm looking for something like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;| time | kubernetes_container_name | log message |&lt;/P&gt;&lt;P&gt;| &lt;SPAN class="t"&gt;2021-09-11&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;21:05:15.590&lt;/SPAN&gt; | contract-mgmt |&amp;nbsp;&lt;SPAN class="t"&gt;2021-09-11&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;21:05:15.590&lt;/SPAN&gt; &lt;SPAN class="t"&gt;INFO&lt;/SPAN&gt; &lt;SPAN class="t"&gt;7&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; [ &lt;/SPAN&gt;&lt;SPAN class="t"&gt;main&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;c.e.h.base.Application&lt;/SPAN&gt; &lt;SPAN class="t"&gt;:&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;Starting&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Application&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;v2.3.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;using&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Java&lt;/SPAN&gt; &lt;SPAN class="t"&gt;11.0.10 |&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;| &lt;SPAN class="t"&gt;2021-09-10&lt;/SPAN&gt; &lt;SPAN class="t"&gt;20:05:15.590&lt;/SPAN&gt; | base-data-mgmt |&amp;nbsp;&lt;SPAN class="t"&gt;2021-09-10&lt;/SPAN&gt; &lt;SPAN class="t"&gt;20:05:15.590&lt;/SPAN&gt; &lt;SPAN class="t"&gt;INFO&lt;/SPAN&gt; &lt;SPAN class="t"&gt;7&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; [ &lt;/SPAN&gt;&lt;SPAN class="t"&gt;main&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;c.e.h.contract.Application&lt;/SPAN&gt; &lt;SPAN class="t"&gt;:&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;Starting&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Application&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;v1.4.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;using&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Java&lt;/SPAN&gt; &lt;SPAN class="t"&gt;11.0.10 |&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 11:53:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567401#M46598</guid>
      <dc:creator>drabbit</dc:creator>
      <dc:date>2021-09-17T11:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: adding columns to dashboard queries</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567413#M46599</link>
      <description>&lt;P&gt;So I misread your OP, but the general theme still applies.&amp;nbsp; Use the &lt;FONT face="courier new,courier"&gt;table&lt;/FONT&gt; command to tell Splunk which columns to display in a table.&amp;nbsp; In this case,&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=foo ```Always specify an index``` "Starting Application" kubernetes_cluster="prod-cluster"
| table time kubernetes_container_name log message&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 17 Sep 2021 13:08:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567413#M46599</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-09-17T13:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: adding columns to dashboard queries</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567610#M46607</link>
      <description>&lt;P&gt;thanks, I got a step further.&lt;/P&gt;&lt;P&gt;When I use the search as you described,&amp;nbsp;I can now see the kubernetes_container_name as a column, but the columns time, log and message are empty. How can I fix that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 08:33:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567610#M46607</guid>
      <dc:creator>drabbit</dc:creator>
      <dc:date>2021-09-20T08:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: adding columns to dashboard queries</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567654#M46609</link>
      <description>&lt;P&gt;The example query expects the fields to be present in the index, but I don't know the contents of your index so the field names may not be exactly right.&amp;nbsp; Adjust the query to match your index or add eval statements as needed to calculate the desired fields.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 12:40:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567654#M46609</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-09-20T12:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: adding columns to dashboard queries</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567656#M46611</link>
      <description>&lt;P&gt;I guess we're already off-topic here. I have absolutley no clue what an index is and how I can find out which fields are in the index. I guess I'll have to study the query stuff more.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 12:47:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567656#M46611</guid>
      <dc:creator>drabbit</dc:creator>
      <dc:date>2021-09-20T12:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: adding columns to dashboard queries</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567657#M46612</link>
      <description>&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/training/courses/intro-to-splunk.html" target="_blank"&gt;https://www.splunk.com/en_us/training/courses/intro-to-splunk.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/training/courses/using-fields.html" target="_blank"&gt;https://www.splunk.com/en_us/training/courses/using-fields.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 12:58:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/adding-columns-to-dashboard-queries/m-p/567657#M46612</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-09-20T12:58:27Z</dc:date>
    </item>
  </channel>
</rss>

