I am using the below tag in my Dashboard and now it's deprecated in the new version, can someone tell me a replacement for the below syntax?
<populatingSearch fieldForValue="EventType" fieldForLabel="EventType" >
<![CDATA[$env$ source=$ProcessingNode$ $stepfilter$ $timerange$ | dedup EventType | $FilterEventType$| table EventType]]>
Thank you gcusello, it works.
Also Can you please let me know the correct tag for classField and linkView ? I saw both are deprecated.
<query>$env$ $inboundeventtypes$ $inboundpublishersources$ $inboundsourcelogfiles$ Step=BusinessEventAcknowledgement OR Step=EventAcknowledgement $timerange$ | dedup RootActivityId| stats count As Total</query>
<option name="classField">range</option>
<option name="field">Total</option>
<option name="linkView">search</option>
<option name="refresh.link.visible">true</option>
<option name="underLabel">Total Received</option>
<set token="showPub">true</set>
<set token="IU">$msgType$</set>
<unset token="sname"></unset>
<unset token="bet"></unset>
<unset token="showSuccess"></unset>
<unset token="showError"></unset>
<option name="drilldown">all</option>
Hi @anilwale,
linkView isn't required: if you enabled drilldown it automatically open the search dashboard.
I 'don't know classField, sorry.
You can see in the Dashboard Examples App all the information you need https://splunkbase.splunk.com/app/1603
let me know if I can help you more, or, please, accept one answer for the other people of Community.
Ciao and happy splunking
P.S.: Karma Points are appreciated 😉
Hi @anilwale ,
please try this:
<input type="dropdown" token="EventType">
$env$ source=$ProcessingNode$ $stepfilter$ $timerange$
| dedup EventType
| $FilterEventType$
| table EventType
beware that I used the field name "Time" for the time picker.