<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Column width in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309647#M92895</link>
    <description>&lt;P&gt;@jip31jip31, you seem to be using Splunk HTML Dashboard while my suggestion code was for Simple XML. You can add a &lt;CODE&gt;hidden html panel&lt;/CODE&gt; to &lt;CODE&gt;row2&lt;/CODE&gt; just before your &lt;CODE&gt;panel&lt;/CODE&gt; with &lt;CODE&gt;table&lt;/CODE&gt;. The table element id is &lt;CODE&gt;tableWithCustomColumnWidth&lt;/CODE&gt; as per my example, which you can change as per your need. The hidden html panel will have CSS override as shown below. Please try out and confirm:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; &amp;lt;div id="row2" class="dashboard-row dashboard-row2"&amp;gt;
        &amp;lt;div id="panel1" class="dashboard-cell" style="width: 50%;" data-depends="$alwaysHideCSSPanel$"&amp;gt;
            &amp;lt;div class="dashboard-panel clearfix"&amp;gt;

                &amp;lt;div class="panel-element-row"&amp;gt;
                    &amp;lt;div id="element1" class="dashboard-element html" style="width: 100%"&amp;gt;
                        &amp;lt;div class="panel-body html"&amp;gt;
                                &amp;lt;style&amp;gt;
                                  #tableWithCustomColumnWidth th[data-sort-key=component] {
                                      width: 80% !important;
                                  }
                                  #customWidth th[data-sort-key=count] {
                                      width: 20% !important;
                                  }
                                &amp;lt;/style&amp;gt;
                        &amp;lt;/div&amp;gt;
                    &amp;lt;/div&amp;gt;
                &amp;lt;/div&amp;gt;
            &amp;lt;/div&amp;gt;
        &amp;lt;/div&amp;gt;
        &amp;lt;div id="panel2" class="dashboard-cell" style="width: 50%;"&amp;gt;
            &amp;lt;div class="dashboard-panel clearfix"&amp;gt;

                &amp;lt;div class="panel-element-row"&amp;gt;
                    &amp;lt;div id="tableWithCustomColumnWidth" class="dashboard-element table" style="width: 100%"&amp;gt;
                         &amp;lt;div class="panel-head"&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 02 Apr 2018 07:09:48 GMT</pubDate>
    <dc:creator>niketn</dc:creator>
    <dc:date>2018-04-02T07:09:48Z</dc:date>
    <item>
      <title>Column width</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309644#M92892</link>
      <description>&lt;P&gt;hi&lt;/P&gt;

&lt;P&gt;i use this code in a report and  i use it in a dashboard&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="*" DisplayName="RCAgentMgr" OR DisplayName="SMS Agent Host" OR DisplayName="Service de transfert intelligent en arrière-plan" Started="false" State="Stopped" | stats count by DisplayName
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;but i dont reach to reduce the width column&lt;BR /&gt;
what i have to do please?&lt;BR /&gt;
thanks&lt;/P&gt;</description>
      <pubDate>Sun, 01 Apr 2018 10:37:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309644#M92892</guid>
      <dc:creator>jip31jip31</dc:creator>
      <dc:date>2018-04-01T10:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: Column width</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309645#M92893</link>
      <description>&lt;P&gt;&lt;STRONG&gt;[Updated Answer]&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Adding Run anywhere dashboard example  in Simple XML to test and confirm&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;@jip31jip31, you can use &lt;A href="https://splunkbase.splunk.com/app/1603/"&gt;Splunk Dashboard Examples&lt;/A&gt; App which has the &lt;CODE&gt;Table With Custom Column Width&lt;/CODE&gt; example for similar kind of use case.&lt;/P&gt;

&lt;P&gt;Try adding the following hidden panel to your Simple XML Dashboard which sets the &lt;CODE&gt;DisplayName&lt;/CODE&gt; width to &lt;CODE&gt;80%&lt;/CODE&gt; and &lt;CODE&gt;count&lt;/CODE&gt; to &lt;CODE&gt;20%&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel depends="$alwaysHideCSSPanel$"&amp;gt;
  &amp;lt;html&amp;gt;
    &amp;lt;style&amp;gt;
      #tableWithCustomColumnWidth th[data-sort-key=DisplayName] {
          width: 80% !important;
      }
      #customWidth th[data-sort-key=count] {
          width: 20% !important;
      }
    &amp;lt;/style&amp;gt;
  &amp;lt;/html&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Following is the complete run anywhere dashboard example based on Splunk's _internal index&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;Table Column Width&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel depends="$alwaysHideCSSPanel$"&amp;gt;
      &amp;lt;html&amp;gt;
        &amp;lt;style&amp;gt;
          #tableWithCustomColumnWidth th[data-sort-key=component] {
              width: 80% !important;
          }
          #customWidth th[data-sort-key=count] {
              width: 20% !important;
          }
        &amp;lt;/style&amp;gt;
      &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table id="tableWithCustomColumnWidth"&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal sourcetype=splunkd log_level!=INFO component=*
| stats count by component&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 01 Apr 2018 15:59:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309645#M92893</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-04-01T15:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Column width</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309646#M92894</link>
      <description>&lt;P&gt;hi niketnilay&lt;/P&gt;

&lt;P&gt;do you mean i have to go in my Dashboard, do modify and open in html?&lt;BR /&gt;
if yes i have catch the code of the concerned Dashboard (see the code below)&lt;BR /&gt;
does i have to put your code in??? thanks&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    &amp;lt;div id="panel1" class="dashboard-cell" style="width: 100%;"&amp;gt;
        &amp;lt;div class="dashboard-panel clearfix"&amp;gt;

            &amp;lt;div class="panel-element-row"&amp;gt;
                &amp;lt;div id="element1" class="dashboard-element table" style="width: 100%"&amp;gt;
                    &amp;lt;div class="panel-head"&amp;gt;
                        &amp;lt;h3&amp;gt;SOC_Critical_Errors_Synthesis&amp;lt;/h3&amp;gt;
                    &amp;lt;/div&amp;gt;
                    &amp;lt;div class="panel-body"&amp;gt;&amp;lt;/div&amp;gt;
                &amp;lt;/div&amp;gt;
            &amp;lt;/div&amp;gt;
        &amp;lt;/div&amp;gt;
    &amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;div id="row2" class="dashboard-row dashboard-row2"&amp;gt;
    &amp;lt;div id="panel2" class="dashboard-cell" style="width: 50%;"&amp;gt;
        &amp;lt;div class="dashboard-panel clearfix"&amp;gt;

            &amp;lt;div class="panel-element-row"&amp;gt;
                &amp;lt;div id="element2" class="dashboard-element table" style="width: 100%"&amp;gt;
                    &amp;lt;div class="panel-head"&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 02 Apr 2018 05:38:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309646#M92894</guid>
      <dc:creator>jip31jip31</dc:creator>
      <dc:date>2018-04-02T05:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Column width</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309647#M92895</link>
      <description>&lt;P&gt;@jip31jip31, you seem to be using Splunk HTML Dashboard while my suggestion code was for Simple XML. You can add a &lt;CODE&gt;hidden html panel&lt;/CODE&gt; to &lt;CODE&gt;row2&lt;/CODE&gt; just before your &lt;CODE&gt;panel&lt;/CODE&gt; with &lt;CODE&gt;table&lt;/CODE&gt;. The table element id is &lt;CODE&gt;tableWithCustomColumnWidth&lt;/CODE&gt; as per my example, which you can change as per your need. The hidden html panel will have CSS override as shown below. Please try out and confirm:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; &amp;lt;div id="row2" class="dashboard-row dashboard-row2"&amp;gt;
        &amp;lt;div id="panel1" class="dashboard-cell" style="width: 50%;" data-depends="$alwaysHideCSSPanel$"&amp;gt;
            &amp;lt;div class="dashboard-panel clearfix"&amp;gt;

                &amp;lt;div class="panel-element-row"&amp;gt;
                    &amp;lt;div id="element1" class="dashboard-element html" style="width: 100%"&amp;gt;
                        &amp;lt;div class="panel-body html"&amp;gt;
                                &amp;lt;style&amp;gt;
                                  #tableWithCustomColumnWidth th[data-sort-key=component] {
                                      width: 80% !important;
                                  }
                                  #customWidth th[data-sort-key=count] {
                                      width: 20% !important;
                                  }
                                &amp;lt;/style&amp;gt;
                        &amp;lt;/div&amp;gt;
                    &amp;lt;/div&amp;gt;
                &amp;lt;/div&amp;gt;
            &amp;lt;/div&amp;gt;
        &amp;lt;/div&amp;gt;
        &amp;lt;div id="panel2" class="dashboard-cell" style="width: 50%;"&amp;gt;
            &amp;lt;div class="dashboard-panel clearfix"&amp;gt;

                &amp;lt;div class="panel-element-row"&amp;gt;
                    &amp;lt;div id="tableWithCustomColumnWidth" class="dashboard-element table" style="width: 100%"&amp;gt;
                         &amp;lt;div class="panel-head"&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 02 Apr 2018 07:09:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309647#M92895</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-04-02T07:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: Column width</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309648#M92896</link>
      <description>&lt;P&gt;sorry but i am totally rookie!&lt;/P&gt;

&lt;P&gt;i have done this but there is a error in last line&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  &amp;lt;table&amp;gt;
    &amp;lt;title&amp;gt;FO_Stopped_Services_Synthesis&amp;lt;/title&amp;gt;
    &amp;lt;search ref="FO_Services_Count"&amp;gt;&amp;lt;/search&amp;gt;
    &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
    &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
    &amp;lt;format type="color" field="count"&amp;gt;
      &amp;lt;colorPalette type="sharedList"&amp;gt;&amp;lt;/colorPalette&amp;gt;
      &amp;lt;scale type="sharedCategory"&amp;gt;&amp;lt;/scale&amp;gt;
    &amp;lt;/format&amp;gt;
     &amp;lt;div id="row2" class="dashboard-row dashboard-row2"&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 02 Apr 2018 09:03:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309648#M92896</guid>
      <dc:creator>jip31jip31</dc:creator>
      <dc:date>2018-04-02T09:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Column width</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309649#M92897</link>
      <description>&lt;P&gt;@jip31jip31 I am confused whether you are using Simple XML or HTML Dashboard in Splunk as the above code example has both which is not correct.&lt;/P&gt;

&lt;P&gt;I have updated my first answer with a Run anywhere dashboard example based on Splunk's _internal index in Simple XML. You should check out the same. If the behavior is what you need, you can convert the same to HTML dashboard and get the corresponding code in HTML which you require.&lt;/P&gt;

&lt;P&gt;As suggested you should also check out Splunk Dashboard Examples App which already has this use case explained through an example.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 09:40:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309649#M92897</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-04-02T09:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Column width</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309650#M92898</link>
      <description>&lt;P&gt;@niketnilay I'm having trouble with the hidden panel in your example.  As I read the Splunk docs, the depends attribute means that the token "$alwaysHideCSSPanel$" must be set in order to display the panel.  Since the token is not set in your example the CSS panel should not appear on the dashboard, correct?&lt;/P&gt;

&lt;P&gt;I pasted the CSS panel into a dashboard, but when I click back on UI to see the dashboard the panel is always there.  Even though I haven't used the  element to set the $alwaysHideCSSPanel$ token.  I feel like I'm missing something... I want to use your CSS to adjust column widths, but I can't get the CSS panel to be invisible.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 16:55:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Column-width/m-p/309650#M92898</guid>
      <dc:creator>crawfs6</dc:creator>
      <dc:date>2020-02-12T16:55:41Z</dc:date>
    </item>
  </channel>
</rss>

