<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I show default search app's dashboard in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-show-default-search-app-s-dashboard/m-p/36155#M8034</link>
    <description>&lt;P&gt;You should probably start by looking the properties of the XML that is generating the "dashboard_live" view, this will show you what searches/saved searches have been used to populate the tables.&lt;/P&gt;

&lt;P&gt;You should start with the XML, you can do this quickly from the dashboard_live view by adding "&lt;CODE&gt;?showsource=1&lt;/CODE&gt;" to the end of the URL, e.g.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;http://mjserver:8000/en-US/app/serach/dashboard_live?showsource=1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;After doing this, you have the raw XML that can used to copy into a new view within your own app. Or more simply... You can also clone the dashboard_live view via the manager (&lt;CODE&gt;Manager &amp;gt;&amp;gt; User Interface &amp;gt;&amp;gt; Views &amp;gt;&amp;gt; clone&lt;/CODE&gt; dashboard_live to your app with a new name), and then modify the searches in the newly cloned view, to filter results as per your requirements.&lt;/P&gt;

&lt;P&gt;I would not recommend changing Splunks's view/searches directly, I would simply "copy and paste" into a new view/search.&lt;/P&gt;

&lt;P&gt;It's not a particularly hard task, but you will just need to filter out your app's events in the searches (perhaps by adding a relevant index in the search or specific source/sourcetype/host combinations, where appropriate).&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;MHibbin&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 12:16:36 GMT</pubDate>
    <dc:creator>MHibbin</dc:creator>
    <dc:date>2020-09-28T12:16:36Z</dc:date>
    <item>
      <title>How do I show default search app's dashboard</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-show-default-search-app-s-dashboard/m-p/36154#M8033</link>
      <description>&lt;P&gt;How Do I display default search app in my app?&lt;/P&gt;

&lt;P&gt;&lt;A href="http://mjserver:8000/en-US/app/search/dashboard_live"&gt;http://mjserver:8000/en-US/app/search/dashboard_live&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Within my app I want to show dashboard_live and display all data(SourceType, source, host, etc..) related to my apps only&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2012 20:39:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-show-default-search-app-s-dashboard/m-p/36154#M8033</guid>
      <dc:creator>jangid</dc:creator>
      <dc:date>2012-08-15T20:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do I show default search app's dashboard</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-show-default-search-app-s-dashboard/m-p/36155#M8034</link>
      <description>&lt;P&gt;You should probably start by looking the properties of the XML that is generating the "dashboard_live" view, this will show you what searches/saved searches have been used to populate the tables.&lt;/P&gt;

&lt;P&gt;You should start with the XML, you can do this quickly from the dashboard_live view by adding "&lt;CODE&gt;?showsource=1&lt;/CODE&gt;" to the end of the URL, e.g.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;http://mjserver:8000/en-US/app/serach/dashboard_live?showsource=1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;After doing this, you have the raw XML that can used to copy into a new view within your own app. Or more simply... You can also clone the dashboard_live view via the manager (&lt;CODE&gt;Manager &amp;gt;&amp;gt; User Interface &amp;gt;&amp;gt; Views &amp;gt;&amp;gt; clone&lt;/CODE&gt; dashboard_live to your app with a new name), and then modify the searches in the newly cloned view, to filter results as per your requirements.&lt;/P&gt;

&lt;P&gt;I would not recommend changing Splunks's view/searches directly, I would simply "copy and paste" into a new view/search.&lt;/P&gt;

&lt;P&gt;It's not a particularly hard task, but you will just need to filter out your app's events in the searches (perhaps by adding a relevant index in the search or specific source/sourcetype/host combinations, where appropriate).&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;MHibbin&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:16:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-show-default-search-app-s-dashboard/m-p/36155#M8034</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2020-09-28T12:16:36Z</dc:date>
    </item>
  </channel>
</rss>

